Network Management
Microsoft ODBC Driver 18 is not validated for the SolarWinds Platform and Server Configuration Monitor (SCM) requires ODBC Driver 17
This article explains why Microsoft ODBC Driver 18 is not validated for use with the SolarWinds Platform, confirms that the ODBC driver only impacts Server Configuration Monitor (SCM), and provides guidance on upgrading to the latest ODBC Driver 17 build to address security vulnerabilities.
First published date
Last published date
Overview
Customers may inquire about upgrading to Microsoft ODBC Driver 18 for SQL Server to address security vulnerabilities such as CVE-2023-36785, CVE-2023-36417, CVE-2023-36420, and CVE-2023-36730.
The Microsoft ODBC driver used by the SolarWinds Platform is specific to the Server Configuration Monitor (SCM) module only. The core SolarWinds Platform services (web console, poller services, etc.) do not rely on the ODBC driver for database connectivity.
SCM ships with and relies on Microsoft ODBC Driver 17 (x64). The SCM uses hardcoded connection strings for its out-of-the-box (OOTB) profiles and policies that are tied to Driver 17. Installing ODBC Driver 18 without Driver 17 will cause SCM profiles and policies to malfunction.
ODBC Driver 17 version 17.10.6.1 includes all security hotfixes delivered in versions 17.10.5 and 18.3.2. Upgrading to the latest ODBC Driver 17 build addresses the known CVEs without introducing compatibility risks.
Product section
Cause
Microsoft ODBC Driver 18 has not been validated or tested for use with the SolarWinds Platform. SCM relies on hardcoded connection strings specifically tied to ODBC Driver 17, and upgrading to Driver 18 without retaining Driver 17 will cause SCM out-of-the-box profiles and policies to malfunction.
Resolution
If SCM is installed
-
Do NOT upgrade to Microsoft ODBC Driver 18. Driver 18 has not been validated for use with SCM and is not compatible with SCM out-of-the-box profiles and policies.
-
Upgrade to the latest build of Microsoft ODBC Driver 17 (17.10.6.1) to address security vulnerabilities. This version includes all security hotfixes from both 17.10.5 and 18.3.2.
-
Download the latest ODBC Driver 17 MSI from the Microsoft ODBC Driver 17 download page.
-
Run the installer on all polling engines (Primary, Additional Polling Engines, HA standbys if applicable).
-
If Driver 18 is required, it is technically possible to install both Driver 17 and Driver 18 side-by-side. However, the connection strings in SCM would need to be manually updated to reference Driver 18. This approach is not recommended as it has not been validated.
If SCM is NOT installed
-
The ODBC driver only impacts the SCM module. The core SolarWinds Platform services (web, poller, etc.) do not use the ODBC driver for database connectivity.
-
Installing or upgrading to ODBC Driver 18 will not directly impact core platform functionality. However, Driver 18 is not officially validated with the SolarWinds Platform.
-
The recommended approach is to upgrade to the latest build of ODBC Driver 17 (17.10.6.1) to address security vulnerabilities while maintaining a known-supported configuration.