A vulnerability scan found that the machine that has the IM fat client installed on it shows that the msxml4 vulnerability is present.
Release: DX UIM 20.4*/ 23.4*
Component: IM fat client (Infrastructure Manager) versions prior to 20.4.8
Versions of Infrastructure Manager prior to 20.4.8 will install:
msxml4.dll
msxml4r.dll
into the C:\Windows\SysWOW64 directory, if they are not already present.
Upgrading to version 20.4.8 of the Infrastructure Manager will remove the reliance on these dll files.
Note: The upgrade/fresh install will not remove these files, if they are present.
And, If running DX UIM 23.4. and IM > 20.4.8, and the files are still there, the files needs to be removed manually as they are no longer needed for IM to run.
The following registry entries are also related, and may be safely removed. It will not cause any harm to leave the registry entries in place, but some security scanners will flag them.
HKEY_CLASSES_ROOT\CLSID\{2933BF90-7B36-11D2-B20E-00C04F983E60}\VersionList
HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{2933BF90-7B36-11D2-B20E-00C04F983E60}\VersionList