Third-Party Package Updates in Microsoft SQL Server App - April 2025

Advisory ID: SVD-2025-0414

CVE ID: Multiple

Published: 2025-04-09

Last Update: 2025-04-09

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Microsoft SQL Server version 2.3.4 and higher, including the following:

PackageRemediationCVESeverity
pcre1Upgraded to pcre2 10.32MultipleHigh

1 Microsoft SQL Server upgraded pcre to pcre2 in microsoftsqlserver/wheels/py36/pymssql-2.2.11-cp36-cp36m-manylinux_2_28_x86_64/pymssql.libs and microsoftsqlserver/wheels/py39/pymssql-2.2.11-cp36-cp36m-manylinux_2_28_x86_64/pymssql.libs folders to remedy multiple CVEs

Solution

Upgrade Microsoft SQL Server to version 2.3.4 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Microsoft SQL Server2.3.4Below 2.3.42.3.4

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.