Java Security Vulnerabilities impact on SEPM and LUA
search cancel

Java Security Vulnerabilities impact on SEPM and LUA

book

Article ID: 453876

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Security scans may return a report that they have found  multiple JAVA vulnerabilities on servers running SEPM and LUA with the below packages :

Jackson (Databind / Core)

YAML / JWT Parsing

Apache Shiro

Jetty (bundled inside a third-party tool only)

Logback

Apache Commons / Connection Pooling

Environment

SEPM

LUA

Resolution

  1. Jackson (Databind / Core)
  • CVE-2022-42003: No Impact
    • SEPM uses a version of this component that is well beyond the affected one.
  • CVE-2022-42004: No Impact
    • SEPM uses a version of this component that is well beyond the affected one.
  • CVE-2020-36518: No Impact
    • SEPM uses a version of this component that is well beyond the affected one.
  • CVE-2021-46877: No Impact
    • SEPM uses a version of this component that is well beyond the affected one.
  • CVE-2026-54512: No Impact
    • This issue requires an optional, uncommon data-processing feature that SEPM does not enable.
  • CVE-2026-54513: No Impact
    • This issue requires the same optional feature as CVE-2026-54512, which SEPM does not enable.
  • CVE-2025-52999: No Impact
    • SEPM uses a version of this component that is well beyond the affected one.
  • CVE-2021-22145: No Impact
    • SEPM uses a version of this component that is well beyond the affected one.
  1. YAML / JWT Parsing
  • CVE-2022-1471: No Impact
    • SEPM does not parse the type of configuration file that this issue affects.
  • CVE-2022-25857: No Impact
    • SEPM does not parse the type of configuration file this issue affects.
  • CVE-2023-1370: No impact
    • This function is only reachable by an already-authenticated administrator, which limits who could ever reach it.
  1. Apache Shiro
  • CVE-2023-34478: No Impact
    • SEPM does not use the affected software component at all.
  • CVE-2020-17523: No Impact
    • SEPM does not use the affected software component.
  • CVE-2021-41303: No Impact
    • SEPM does not use the affected software component.
  • CVE-2022-40664: No Impact
    • SEPM does not use the affected software component.
  • CVE-2022-32532: No Impact
    • SEPM does not use the affected software component.
  • CVE-2020-13933: No Impact
    • SEPM does not use the affected software component.
  1. Jetty (bundled inside a third-party tool only)
  • CVE-2026-2332: No impact
    • The affected component ships only inside a bundled third-party administrative tool that requires authentication and runs only over an encrypted connection.
  • CVE-2019-17638: No impact
    • SEPM already uses the exact version of this component that fixes this issue.
  • CVE-2021-28165: Not affected. 
    • The tool requires administrator authentication over an encrypted connection.
  1. Logback
  • CVE-2017-5929: No Impact
    • SEPM uses a version well beyond the affected one and does not use the specific feature this issue depends on.
  • CVE-2021-42550: No Impact
    • SEPM uses a version well beyond the affected one and does not use the specific feature this issue depends on.
  1. Apache Commons / Connection Pooling
  • CVE-2025-48734: No Impact
    • SEPM's code does not use the specific feature this issue depends on.
  • CVE-2023-24998: No Impact (v14.4) / Mitigated (v14.3 RU9)
    • The affected feature was fully removed in 14.4; in 14.3 RU9 it still exists but can only be reached by an authenticated session.
  • CVE-2026-27727: No Impact
    • SEPM does not use the connection-pooling technology this issue affects.

 

LUA is not vulnerable to any of the reported CVEs because no management, JMX, or REST configuration is used.