This article provides a security assessment regarding the impact of CVE-2025-22228 on the Symantec Protection Engine (SPE) environment.
Symantec Protection Engine (SPE) 9.x
Symantec Protection Engine is not impacted by CVE-2025-22228. The vulnerability specifically targets the following method: BCryptPasswordEncoder.matches(CharSequence,String). SPE does not utilize this method within its architecture.
CRE-21543