Vulnerability scanners may report high or critical vulnerabilities associated with Telerik.Windows.Controls.dll within the Javelin installation path.
C:\Program Files\Grid-Tools\Javelin\Telerik.Windows.Controls.dllAll supported Javelin releases.
These vulnerabilities reside in the 3rd-party Telerik UI for WPF component used by the Javelin UI.
NOTE: The TDM Portal uses the JaaaavelinExecutor.exe (command line executable), which is not impacted.
TDM Engineering has analyzed the risk for each CVE based on Javelin's specific implementation:
RichTextBox, PdfViewer, and Spreadsheet controls. While the vulnerable assemblies exist on disk, these specific controls are never instantiated or used within the Javelin application. Per Telerik's security advisory, applications that do not use these controls are not affected.RadDiagram control).