Security scans may flag Service Desk Manager (SDM) servers for vulnerability CVE-2025-41254 (Spring Framework STOMP CSRF). This is often associated with Plugin 275873 and identifies vulnerable versions of spring-core-*.jar (e.g., version 5.3.39) in the following typical paths:
NX_ROOT\java\lib\CXF\spring-core-5.3.39.jar
NX_ROOT\bopcfg\www\CATALINA_BASE\webapps\cxf\WEB-INF\lib\spring-core-5.3.39.jar
Product: CA Service Management - Service Desk Manager
Release: 17.4
The vulnerability exists in Spring Framework versions (5.3.x < 5.3.46, 6.1.x < 6.1.24, 6.2.x < 6.2.12) when using the STOMP protocol for WebSocket applications.
The Engineering team has confirmed that Service Desk Manager is not impacted by CVE-2025-41254.
The vulnerability is only exploitable if the application utilizes Spring's STOMP protocol for WebSocket communication. Service Desk Manager does not use WebSocket communication or the STOMP protocol; therefore, the presence of the identified .jar files does not pose a security risk in the context of this CVE SDM vulnerability CVE-2025-41254 Plugin 275873.
Although SDM is not vulnerable, Broadcom will upgrade the underlying components in future releases to address the scan results:
SDM 17.5: The CXF version will be upgraded to 4.x, which is compatible with Spring Core 7.x.