Starting from NFA 23.3.13, we have added support for the 64 bit MySQL ODBC connector.
In the recent security scan finding it was detected that there is a 32 bit MySQL ODBC connector version 8.0.37 under the following path:
C:\Program File(x86)\MySQL\Connector ODBC 8.0\
We would like to check if the 32 bit MySQL ODBC connector can be uninstalled from NFA console server.
DX NetOps Network flow Analysis 23.3.13+
NFA 23.3.13+ releases use BOTH the 32-Bit and 64-Bit ODBC connectors.
However, scanners generally do not check for version branches and only look at the version numbers. As a result, the 32-bit versions of the ODBC Connector may be flagged as vulnerable in spite of the fact that it is newer (and fixes more vulnerabilities) than a 64-Bit ODBC connector with a "higher" version number.
NFA 23.3.13 release uses both the 8.0.37 (32-bit) and 8.4 (64-bit) MySQL connectors.
According to MySQL Connector/ODBC Downloads:
However, scanners generally do not check for version branches and only look at the version numbers. As a result, while 8.0.37 should have the same vulnerabilities fixed as other versions, it may still flag differently due to this oversight.
Both connectors are required for NFA to function properly. The ETA for a future release where all NFA components will support 64-bit is still unknown at this point of time.
If a version of the 32-bit ODBC connector higher than 8.0.37 is required, please open a Support ticket for assistance.