<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerability CVE-2022-22970, CVE-2022-22971 - /replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar in Qlik Replicate</title>
    <link>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972768#M3558</link>
    <description>&lt;P&gt;Case#&amp;nbsp;00050175: Vulnerabilities CVE-2022-22970, CVE-2022-22971 is created for this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;</description>
    <pubDate>Thu, 25 Aug 2022 03:12:51 GMT</pubDate>
    <dc:creator>vijaynarayanan</dc:creator>
    <dc:date>2022-08-25T03:12:51Z</dc:date>
    <item>
      <title>Vulnerability CVE-2022-22970, CVE-2022-22971 - /replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1969507#M3469</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;Vulnerabilities CVE-2022-22970, CVE-2022-22971 ("Spring Framework Denial of Service (DoS) Data Binding Vulnerability") are detected &amp;nbsp;for the Qlik replicate spring core jar file "/replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do we have remediation for the detected vulnerability? We need to update the spring-core jar at the earliest.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;~ VJ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 06:54:07 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1969507#M3469</guid>
      <dc:creator>vijaynarayanan</dc:creator>
      <dc:date>2022-08-17T06:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability CVE-2022-22970, CVE-2022-22971 - /replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1969526#M3470</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/182336"&gt;@vijaynarayanan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CVE-2022-22970:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This CVE is a DDoS in the Spring file upload function ( a servlet). QDI products do not use this functionality of Spring (Spring is not used in QDI to offer networking services) and thus, there is no actual risk. Qlik will update this component in the 2022.11 release - since no security issue exists, the change is not updated in older releases.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2022-22971:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This CVE is in Spring's STOMP protocol. QDI products do not use this functionality of Spring and thus, there is no actual risk. Qlik will update this component in the 2022.11 release - since no security issue exists, the change is not updated in older releases.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 07:20:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1969526#M3470</guid>
      <dc:creator>Arun_Arasu</dc:creator>
      <dc:date>2022-08-17T07:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability CVE-2022-22970, CVE-2022-22971 - /replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972249#M3532</link>
      <description>&lt;P&gt;Team,&lt;/P&gt;
&lt;P&gt;Do we have the knowledge base article that explains the same information? I need to update my organization with the details.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 04:46:01 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972249#M3532</guid>
      <dc:creator>vijaynarayanan</dc:creator>
      <dc:date>2022-08-24T04:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability CVE-2022-22970, CVE-2022-22971 - /replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972512#M3535</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/182336"&gt;@vijaynarayanan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Unfortunately , there are no&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;knowledge base article that explains the same information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Arun&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 12:42:14 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972512#M3535</guid>
      <dc:creator>Arun_Arasu</dc:creator>
      <dc:date>2022-08-24T12:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability CVE-2022-22970, CVE-2022-22971 - /replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972650#M3546</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/163799"&gt;@Arun_Arasu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My Org is looking for the information in knowledge base article to get the exception. Could you guide on the right process to get that information?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 16:45:56 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972650#M3546</guid>
      <dc:creator>vijaynarayanan</dc:creator>
      <dc:date>2022-08-24T16:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability CVE-2022-22970, CVE-2022-22971 - /replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972678#M3549</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/user/viewprofilepage/user-id/182336" target="_blank"&gt;@vijaynarayanan&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I checked again but as Arun mentioned, no one has created knowledge base article yet on&amp;nbsp;Vulnerability CVE-2022-22970, CVE-2022-22971.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you need any further assistance on this please create a case, so that our technical support team can assist you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Naren&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 17:49:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972678#M3549</guid>
      <dc:creator>narendersarva</dc:creator>
      <dc:date>2022-08-24T17:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability CVE-2022-22970, CVE-2022-22971 - /replicate/endpoint_srv/externals/spring-core-5.1.9.RELEASE.jar</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972768#M3558</link>
      <description>&lt;P&gt;Case#&amp;nbsp;00050175: Vulnerabilities CVE-2022-22970, CVE-2022-22971 is created for this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;</description>
      <pubDate>Thu, 25 Aug 2022 03:12:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Vulnerability-CVE-2022-22970-CVE-2022-22971-replicate-endpoint/m-p/1972768#M3558</guid>
      <dc:creator>vijaynarayanan</dc:creator>
      <dc:date>2022-08-25T03:12:51Z</dc:date>
    </item>
  </channel>
</rss>

