BusinessObjects Board

Vulnerability : Microsoft Visual C++ 2010 Redistributable Package Detected

We have received the info from our security department. Obsolete Software: Microsoft Visual C++ 2010 Redistributable Package Detected. This has to be removed from our BO servers ASAP.

We are on BOBJ 4.2 SP9 and we see Microsoft Visual C++ 2010 Redistributable are present on the BO server and we also have Microsoft Visual C++ 2015-22 on our BO server.

Found a sap KBA 2948372 - Can Microsoft Visual C++ 2010 redistributable packages be removed in server and client BI machines ?

The KBA says Microsoft Visual C++ 2010 redistributable packages should not be uninstalled from both server and client, This will likely cause key functionality of the product to no longer work.

SAP says Microsoft Visual C++ 2010 is not used in BO 4.3 onwards and we can delete it once we move to BO 4.3.

Can you suggest how to fix the vulnerability issue in our current BO 4.2 sp9 version