Network Management

Security software flagging SQL Server Compact Edition 3.5 and 4.0 as vulnerability

This article addresses a vulnerability detected by NPM in SQL Server Compact Edition 3.5. Scanning shows EOL/Obsolete Software: Microsoft SQL Server Compact 3.5 Detected and you are prompted upgrade to SQL Server Compact 4.

First published date

11/9/2018 12:45 AM

Last published date

10/21/2025 3:44 PM

Overview

The vulnerability scanner detects that Microsoft SQL Server Compact 3.5 and 4.0 (32- and 64-bit) is a vulnerability and recommends that the user uninstall the service.

SQL Server Compact is a small-footprint, in-process database engine that allows developers to build robust applications for Windows Desktops and Mobile Devices.

Product section

Network Performance Monitor

Cause

Product Limitation

Resolution

  • Fixed in SolarWinds Platform 2018.4 as it uses 4.0 version, so upgrade to 2018.4 or higher version.

  • The later versions of SolarWinds Platform do not need the Microsoft SQL Server Compact 3.5. We moved to version 4.0 several releases ago and now in 2020.2.6, Collector and JE services use SQLite. Therefore, there will be no impact if you decide to uninstall/delete it.