<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208 in Qlik Replicate</title>
    <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2112791#M7224</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Our security team run a security scan over this replicate server with version&amp;nbsp;&lt;SPAN&gt;2022.11.0.208 and found the fact this java version is vulnerable by some CVE issues.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I´ve found this question related to this issue, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Question-regarding-Qlik-Replicate-and-a-Java-SE-Vulnerability/ta-p/2035633" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Official-Support-Articles/Question-regarding-Qlik-Replicate-and-a-Java-SE-Vulnerability/ta-p/2035633&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and the official answer is just upgrade java within the same server and no qlik replicate upgrade is needed. But in our server we only have the replicate java running, no other java is installed on this server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That means just replace the binaries under folder&amp;nbsp;/opt/attunity/replicate/jvm/ ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How to do that in a stable way?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Sep 2023 09:39:20 GMT</pubDate>
    <dc:creator>danielrf</dc:creator>
    <dc:date>2023-09-04T09:39:20Z</dc:date>
    <item>
      <title>Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2112791#M7224</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Our security team run a security scan over this replicate server with version&amp;nbsp;&lt;SPAN&gt;2022.11.0.208 and found the fact this java version is vulnerable by some CVE issues.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I´ve found this question related to this issue, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Question-regarding-Qlik-Replicate-and-a-Java-SE-Vulnerability/ta-p/2035633" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Official-Support-Articles/Question-regarding-Qlik-Replicate-and-a-Java-SE-Vulnerability/ta-p/2035633&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and the official answer is just upgrade java within the same server and no qlik replicate upgrade is needed. But in our server we only have the replicate java running, no other java is installed on this server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That means just replace the binaries under folder&amp;nbsp;/opt/attunity/replicate/jvm/ ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How to do that in a stable way?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 09:39:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2112791#M7224</guid>
      <dc:creator>danielrf</dc:creator>
      <dc:date>2023-09-04T09:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2113016#M7234</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/128751"&gt;@danielrf&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Welcome to Qlik Community forum and thanks for reaching out here!&lt;/P&gt;
&lt;P&gt;In general the steps should be:&lt;/P&gt;
&lt;P&gt;1. Stop Replicate tasks manually&lt;/P&gt;
&lt;P&gt;2. Stop Replicate Services&lt;/P&gt;
&lt;P&gt;3. Rename the&amp;nbsp;&lt;SPAN&gt;folder&amp;nbsp;&lt;FONT face="courier new,courier"&gt;/opt/attunity/replicate/jvm/&lt;/FONT&gt; (for example to "jvm.11.0.14")&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. Paste higher version (eg 11.0.17) "jvm" folder the same location (for example&amp;nbsp;&lt;FONT face="courier new,courier"&gt;/opt/attunity/replicate/jvm/&lt;/FONT&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5. Startup Services and check if all works as expected&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;6. RESUME tasks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'd like to suggest getting the version 11.0.17 jvm folder by a fresh installation on a standalone machine, for example &lt;A title="download Replicate&amp;nbsp;May 2023 SR1" href="https://github.com/qlik-download/replicate/releases/tag/v2023.5.1" target="_blank" rel="noopener"&gt;download Replicate&amp;nbsp;May 2023 SR1&lt;/A&gt;. Please conduct careful acceptance test on lower environment prior to implement on PROD system.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Feel free to let us know if you need any additional assistance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;John.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 04:13:44 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2113016#M7234</guid>
      <dc:creator>john_wang</dc:creator>
      <dc:date>2023-09-05T04:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2114397#M7266</link>
      <description>&lt;P&gt;Hi John,&lt;/P&gt;
&lt;P&gt;Thanks for your fast response!&lt;/P&gt;
&lt;P&gt;Our security team adviced to install jvm 11.0.20 or greater but the qlik replicate version may 2023 comes with the 11.0.17 . still vulnerable...&lt;/P&gt;
&lt;P&gt;So I think you need to open an issue to upgrade the jvm to a secure java version (upper or equal to 11.0.20)&lt;/P&gt;
&lt;P&gt;$ /opt/attunity/replicate/jvm/bin/java --version&lt;BR /&gt;openjdk 11.0.17 2022-10-18&lt;BR /&gt;IBM Semeru Runtime Open Edition 11.0.17.0 (build 11.0.17+8)&lt;BR /&gt;Eclipse OpenJ9 VM 11.0.17.0 (build openj9-0.35.0, JRE 11 Linux amd64-64-Bit Compressed References 20221031_559 (JIT enabled, AOT enabled)&lt;BR /&gt;OpenJ9 - e04a7f6c1&lt;BR /&gt;OMR - 85a21674f&lt;BR /&gt;JCL - a94c231303 based on jdk-11.0.17+8)&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 15:10:01 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2114397#M7266</guid>
      <dc:creator>danielrf</dc:creator>
      <dc:date>2023-09-07T15:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2115147#M7288</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/128751"&gt;@danielrf&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thanks for your feedback.&lt;/P&gt;
&lt;P&gt;Qlik Replicate 2023.5 (GA - SP03) contains JVM&amp;nbsp;&lt;SPAN&gt;11.0.17. This is the latest official certified JVM version up to today. The higher versions JVM (includes 11.0.19, 11.0.20.1) works for me with Replicate 2022.11 on Linux and Replicate 2023.5 on Windows. however these are our support team internal smoking tests only, this is not Qlik R&amp;amp;D official QA Tests. We'd like to suggest:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1- Implement certified JVM version 11.0.17 at PROD system at present; or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2- Open Feature Request and ask for higher versions certification; however it takes time,&amp;nbsp; and Qlik may not could release JVM certificated versions frequently.&amp;nbsp; or,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3- Replace JVM folder with latest build , v11.0.20.1 and conduct careful acceptance test at lower env, implement it at PROD system after all the items pass test successfully at UAT/TEST env.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The JVM used in our tests:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;[root@CentOS85 bin]# ./java -version&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;openjdk version "11.0.20.1" 2023-08-24&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;IBM Semeru Runtime Open Edition 11.0.20.1 (build 11.0.20.1+1)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Eclipse OpenJ9 VM 11.0.20.1 (build openj9-0.40.0, JRE 11 Linux amd64-64-Bit Compressed References 20230824_836 (JIT enabled, AOT enabled)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;OpenJ9 - d12d10c9e&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;OMR - e80bff83b&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;JCL - 0880e8df04 based on jdk-11.0.20.1+1)&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;John.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 06:38:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2115147#M7288</guid>
      <dc:creator>john_wang</dc:creator>
      <dc:date>2023-09-09T06:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2126965#M7649</link>
      <description>&lt;P&gt;Hi John,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your suggestions, we will follow your advice.&lt;/P&gt;
&lt;P&gt;How can I open a feature request for that? I can not find the way to do that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 09:42:00 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2126965#M7649</guid>
      <dc:creator>danielrf</dc:creator>
      <dc:date>2023-10-10T09:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2126973#M7651</link>
      <description>&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Hello Team,&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;To get started please see our article: "Getting Started with Ideas": &lt;A href="https://community.qlik.com/t5/Ideation/ct-p/qlik-product-insight" target="_blank"&gt;https://community.qlik.com/t5/Ideation/ct-p/qlik-product-insight&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;You will be required to have a Qlik ID to log on to the Community which is not the same as your support portal login. If you have previously registered for a Qlik ID such as the one you use to access the downloads site, you can use the same to log on for the Community. The first-time accessing Community with a Qlik idea will prompt for a username alias to be used when posting to the Community. This alias is not a logon but for display purposes when posting. You can register at the login screen if you do not have a Qlik ID. The Ideas blog post will provide information on how to use the Ideas board and how to access it.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Thank you,&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Sushil Kumar&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 09:56:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2126973#M7651</guid>
      <dc:creator>SushilKumar</dc:creator>
      <dc:date>2023-10-10T09:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2126981#M7652</link>
      <description>&lt;P&gt;I am afraid that link doesnt work&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 10:14:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2126981#M7652</guid>
      <dc:creator>danielrf</dc:creator>
      <dc:date>2023-10-10T10:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2126983#M7653</link>
      <description>&lt;PRE&gt;{"errors":[{"title":"State verification failed","detail":"State not valid, missing request forgery protection","code":"STATE-1","status":"401"}],"traceId":"0000000000000000f5f265c1aec5a3b8"}&lt;/PRE&gt;</description>
      <pubDate>Tue, 10 Oct 2023 10:15:39 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2126983#M7653</guid>
      <dc:creator>danielrf</dc:creator>
      <dc:date>2023-10-10T10:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2127031#M7654</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;Not Sure why it's not working for you. Could you please check once you logged in the community. as we normally share link post verification.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check this link as well.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/About-Ideation/ct-p/qlik-aboutideation" target="_blank"&gt;About Ideation | Qlik Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sushil Kumar&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 12:05:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2127031#M7654</guid>
      <dc:creator>SushilKumar</dc:creator>
      <dc:date>2023-10-10T12:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Java 11.0.14 vulnerable on Qlik Replicate Version 2022.11.0.208</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2127567#M7673</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;I think this page is an iframe embeded, and the security policy of my browser , handled by admins, is not allow iframes.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 14:54:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Java-11-0-14-vulnerable-on-Qlik-Replicate-Version-2022-11-0-208/m-p/2127567#M7673</guid>
      <dc:creator>danielrf</dc:creator>
      <dc:date>2023-10-11T14:54:54Z</dc:date>
    </item>
  </channel>
</rss>

