We have detected vulnerabilities relating to ODBC Connectors in NFA. What are recommended versions?
search cancel

We have detected vulnerabilities relating to ODBC Connectors in NFA. What are recommended versions?

book

Article ID: 391447

calendar_today

Updated On:

Products

Network Observability Network Flow Analysis

Issue/Introduction

Our scanners have detected security vulnerabilities and we are concerned with the version numbers indicated by the tools 

  • MySQL ODBC Connector 8.4.0 (64-Bit)
  • MySQL ODBC Connector 9.1.0 (64-Bit)
  • MySQL ODBC Connector 8.0.37 (32-Bit)
  • MySQL ODBC Connector 8.0.40 (32-Bit)

Resolution

There are two ODBC connectors, one being 32-bit and the other 64-bit, and NFA requires them both.  The version numbers for these release can be confusing.  To explain:

In in NFA 23.3.13:

64 bit release in NFA is = 8.4.0  -  This tool is found in C:\Program Files\  -  See release notes to mysql ODBC 64 bit release 2024-04-30
https://dev.mysql.com/doc/relnotes/connector-odbc/en/news-8-4-0.html  

32 bit release in NFA is = 8.0.37 -  This tool is found in C:\Program Files (x86)\  - See release notes to mysql ODBC 32 bit release notes from 2024-04-30

https://dev.mysql.com/doc/relnotes/connector-odbc/en/news-8-0-37.html

 

As of NFA release is 24.3.7:

64bit ODBC = version 9.1.0  (release in NFA 24.3.4 )
https://dev.mysql.com/doc/relnotes/connector-odbc/en/news-9-1-0.html  from 2024-10-15  

32bit ODBC = Version 8.0.37 (release in NFA 24.x.x)
https://dev.mysql.com/doc/relnotes/connector-odbc/en/news-8-0-37.html  from 2024-04-30

 

We do not recommend manually upgrading 32bit ODBC, instead please upgrade to NFA 24.3.5+ or newer.  
64 bit ODBC can not be upgraded manually.

 

Additional Information