Skip to main content
Answer

MS SQL Management studio(ODBC) Vulnerability on Commserve

  • August 19, 2025
  • 2 replies
  • 194 views

Forum|alt.badge.img+8

Hi Team,

 

We got one MS SQL Management studio(ODBC) Vulnerability on Commserve.

 

Plugin Output:
Path : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\IDE\Mashup\ODBC Drivers\Simba Spark ODBC Driver\LibCurl32.DllA\libcurl.dll
Installed version : 7.66.0.0
Fixed version : 8.9.1


As per commvault case 250807-187(this case is closed),

This is not a SQL core vulnerability but a SSMS vulnerability.
You can either ignore it or upgrade your SSMS and ODBC drives to remediate that.
Commvault is not affected by this vulnerability.

 

We are upgrading from 11.32 to 11.36 for production before that we did upgrade of test commserve to 11.36. .I see the SQL version there is also upgraded from sql 2019 to sql2022.SS Management studio is still 18.x.
If I upgrade SSMS to 20.x(as per Support advise) will there be any impact on Commserve operations.I am reaching here since SQL server is used by Commvault stack and want to know if it works for SSMS 20.x also.Do I need to uninstall SSMS 18.x first? 

Best answer by Pradeep

Hi ​@AbdulIkram ,

You may proceed with upgrading SQL Server Management Studio alone, as this will not impact the CommServe database. SSMS is only a GUI interface used for managing the SQL Server database.

If you have a question or comment, please create a topic

2 replies

Forum|alt.badge.img+12
  • Vaulter
  • Answer
  • August 20, 2025

Hi ​@AbdulIkram ,

You may proceed with upgrading SQL Server Management Studio alone, as this will not impact the CommServe database. SSMS is only a GUI interface used for managing the SQL Server database.


Forum|alt.badge.img+8
  • Author
  • Byte
  • August 21, 2025

Thank you.