SDM CVE-2025-41254
search cancel

SDM CVE-2025-41254

book

Article ID: 440618

calendar_today

Updated On:

Products

CA Service Management - Service Desk Manager CA Service Desk Manager

Issue/Introduction

Security scans may flag Service Desk Manager (SDM) servers for vulnerability CVE-2025-41254 (Spring Framework STOMP CSRF). This is often associated with Plugin 275873 and identifies vulnerable versions of spring-core-*.jar (e.g., version 5.3.39) in the following typical paths:

NX_ROOT\java\lib\CXF\spring-core-5.3.39.jar
NX_ROOT\bopcfg\www\CATALINA_BASE\webapps\cxf\WEB-INF\lib\spring-core-5.3.39.jar

Environment

Product: CA Service Management - Service Desk Manager
Release: 17.4 

Cause

The vulnerability exists in Spring Framework versions (5.3.x < 5.3.46, 6.1.x < 6.1.24, 6.2.x < 6.2.12) when using the STOMP protocol for WebSocket applications.

Resolution

The Engineering team has confirmed that Service Desk Manager is not impacted by CVE-2025-41254.

The vulnerability is only exploitable if the application utilizes Spring's STOMP protocol for WebSocket communication. Service Desk Manager does not use WebSocket communication or the STOMP protocol; therefore, the presence of the identified .jar files does not pose a security risk in the context of this CVE SDM vulnerability CVE-2025-41254 Plugin 275873.

Although SDM is not vulnerable, Broadcom will upgrade the underlying components in future releases to address the scan results:

SDM 17.5: The CXF version will be upgraded to 4.x, which is compatible with Spring Core 7.x.