Comprehensive data protection for all workloads
Post Reply
JaxIsland7575
Veteran
Posts: 391
Liked: 107 times
Joined: Apr 27, 2015 1:59 pm
Full Name: Ryan Jacksland
Location: NY, USA
Contact:

MS SQL Compact 3.5 Vulnerability Found

Post by JaxIsland7575 »

I am doing a security / vulnerability assessment and the VBR server was found to have EOL/Obsolete Software on it. It is reporting this on MA SQL Compact 3.5 which is installed. This is a local DB all features installed on this same physical server running the latest VBR version. My question is about fixing this, can I remove it? Can I upgrade it to v4, what is it and do I need it?

This item in the report is listed as the highest critical vulnerability so if someone could assist me is resolving it, I would appreciate it.

Thank you!
VMCE v9
csydas
Expert
Posts: 193
Liked: 47 times
Joined: Jan 16, 2018 5:14 pm
Full Name: Harvey Carel
Contact:

Re: MS SQL Compact 3.5 Vulnerability Found

Post by csydas »

Should be fine. Veeam packages MSSQL Express, and recommends running on Standard for more serious workloads. So if it's "working", it's not supported (I honestly don't know the functional differences between MSSQL Compact and Express...)

https://helpcenter.veeam.com/docs/backu ... kup_server

Regardless, take a Config Backup and a DB backup before you make a decision, and either just jump over to SQL Express/Standard or do the upgrade.
bdufour
Expert
Posts: 206
Liked: 41 times
Joined: Nov 01, 2017 8:52 pm
Full Name: blake dufour
Contact:

Re: MS SQL Compact 3.5 Vulnerability Found

Post by bdufour »

i dont think sql compact is related to veeam, according to my knowledge. sql compact is mostly used by developers.
Gostev
Chief Product Officer
Posts: 31814
Liked: 7302 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: MS SQL Compact 3.5 Vulnerability Found

Post by Gostev »

Veeam Backup & Replication does not use SQL Compact.
JaxIsland7575
Veteran
Posts: 391
Liked: 107 times
Joined: Apr 27, 2015 1:59 pm
Full Name: Ryan Jacksland
Location: NY, USA
Contact:

Re: MS SQL Compact 3.5 Vulnerability Found

Post by JaxIsland7575 »

I installed v4. Had to manually remove the program files folder for 3.5 and rebooted. Vulnerability scan came back clean and VBR is functioning normally, so I guess its good to go.

Thank you for the clarification Gostev!
VMCE v9
Post Reply

Who is online

Users browsing this forum: Semrush [Bot] and 78 guests