Remediation of CVE-2024-22243 for Service Desk Manager
search cancel

Remediation of CVE-2024-22243 for Service Desk Manager

book

Article ID: 379441

calendar_today

Updated On:

Products

CA Service Management - Service Desk Manager CA Service Desk Manager

Issue/Introduction

According to CVE-2024-22243, there is a vulnerability in the Spring framework (spring-core-XXXX.jar) in the following releases:

6.1.0 - 6.1.3
6.0.0 - 6.0.16
5.3.0 - 5.3.31

Which version of Service Desk Manager 17.4 addresses this vulnerability?

Environment

Release 17.4 (GA - RU2)

CA Service Desk Manager

Resolution

The version of the spring-core jar file that is referenced in CVE-2024-22243 is version 5.3.37 as of 17.4 RU3 and will be addressed at this release.

Additional Information

As of the current writing (early Oct, 2024), 17.4 RU3 is anticipated for release in late Oct, 2024.