According to CVE-2024-22243, there is a vulnerability in the Spring framework (spring-core-XXXX.jar) in the following releases:
6.1.0 - 6.1.3
6.0.0 - 6.0.16
5.3.0 - 5.3.31
Which version of Service Desk Manager 17.4 addresses this vulnerability?
Release 17.4 (GA - RU2)
CA Service Desk Manager
The version of the spring-core jar file that is referenced in CVE-2024-22243 is version 5.3.37 as of 17.4 RU3 and will be addressed at this release.
As of the current writing (early Oct, 2024), 17.4 RU3 is anticipated for release in late Oct, 2024.