Issue:
Can I verify if WithSecure Policy Manager is affected by the vulnerability, CVE-2021-42392?
Resolution:
The H2 Console is not enabled in the Policy Manager Server by default.
Even if the H2 Console has been enabled through the advanced configuration for the Policy Manager Server, there is no way to inject the database URL into it.
Hence, the Policy Manager Server is not affected by this vulnerability.
Article no: 000037329