Third-Party Package Updates in Microsoft SQL Server App - April 2025
Advisory ID: SVD-2025-0414
CVE ID: Multiple
Published: 2025-04-09
Last Update: 2025-04-09
Description
Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Microsoft SQL Server version 2.3.4 and higher, including the following:
Package | Remediation | CVE | Severity |
---|---|---|---|
pcre1 | Upgraded to pcre2 10.32 | Multiple | High |
1 Microsoft SQL Server upgraded pcre to pcre2 in microsoftsqlserver/wheels/py36/pymssql-2.2.11-cp36-cp36m-manylinux_2_28_x86_64/pymssql.libs and microsoftsqlserver/wheels/py39/pymssql-2.2.11-cp36-cp36m-manylinux_2_28_x86_64/pymssql.libs folders to remedy multiple CVEs
Solution
Upgrade Microsoft SQL Server to version 2.3.4 or higher.
Product Status
Product | Version | Component | Affected Version | Fix Version |
---|---|---|---|---|
Microsoft SQL Server | 2.3.4 | Below 2.3.4 | 2.3.4 |
Severity
For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.