<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vulnerabilities OpenSSL 1.1.0 in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/m-p/2480937#M29201</link>
    <description>&lt;P&gt;Hello!&lt;BR /&gt;There are several outdated OpenSSL libs with vulnerabilities in connector package&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BuTbka_0-1726044142026.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/171522iEE81D06EC062D8F0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BuTbka_0-1726044142026.png" alt="BuTbka_0-1726044142026.png" /&gt;&lt;/span&gt;&lt;BR /&gt;QS May 2024 Patch 5&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Nessus scan results:&lt;BR /&gt;[&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1h (C:\\Program files\\Qlik\\Sense\\Repository\\Postgresql\\12.5\\Bin\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Hive\\Lib\\Libcurl64.dlla\\Openssl64.dlla\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Hive\\Lib\\Openssl64.dlla\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Impala\\Lib\\Openssl64.dlla\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1n (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Mysql\\Lib\\Openssl64.dlla\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.0j (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Phoenix\\Lib\\Openssl64.dlla\\)"&lt;BR /&gt;]&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Where we can download updated drivers or libs?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2025 16:21:29 GMT</pubDate>
    <dc:creator>BuTbka</dc:creator>
    <dc:date>2025-01-29T16:21:29Z</dc:date>
    <item>
      <title>Vulnerabilities OpenSSL 1.1.0</title>
      <link>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/m-p/2480937#M29201</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;There are several outdated OpenSSL libs with vulnerabilities in connector package&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BuTbka_0-1726044142026.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/171522iEE81D06EC062D8F0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BuTbka_0-1726044142026.png" alt="BuTbka_0-1726044142026.png" /&gt;&lt;/span&gt;&lt;BR /&gt;QS May 2024 Patch 5&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Nessus scan results:&lt;BR /&gt;[&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1h (C:\\Program files\\Qlik\\Sense\\Repository\\Postgresql\\12.5\\Bin\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Hive\\Lib\\Libcurl64.dlla\\Openssl64.dlla\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Hive\\Lib\\Openssl64.dlla\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Impala\\Lib\\Openssl64.dlla\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.1n (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Mysql\\Lib\\Openssl64.dlla\\)",&lt;BR /&gt;"OpenSSL Project OpenSSL 1.1.0j (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Phoenix\\Lib\\Openssl64.dlla\\)"&lt;BR /&gt;]&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Where we can download updated drivers or libs?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 16:21:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/m-p/2480937#M29201</guid>
      <dc:creator>BuTbka</dc:creator>
      <dc:date>2025-01-29T16:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerabilities OpenSSL 1.1.0</title>
      <link>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/m-p/2511826#M31768</link>
      <description>&lt;P&gt;Have this been addressed by anyone? Patch 11 still has this version on our instances, upgrading to Patch 15 came with the following:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tin_u_0-1743066486981.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/179028i7375A99A0967E951/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tin_u_0-1743066486981.png" alt="tin_u_0-1743066486981.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 09:08:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/m-p/2511826#M31768</guid>
      <dc:creator>tin_u</dc:creator>
      <dc:date>2025-03-27T09:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerabilities OpenSSL 1.1.0</title>
      <link>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/m-p/2517987#M31920</link>
      <description>&lt;P&gt;I am also facing the same issue, have opened the ticket with Qlik support and here is the answer i have received.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It seems that Qlik Sense Enterprise has OpenSSL libraries at&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;C:\program files\common files\qlik\custom data\qvodbcconnectorpackage\...\lib&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;OpenSSL 3.0.15 has security fixes - &lt;A href="https://openssl-library.org/news/openssl-3.0-notes/index.html" target="_blank"&gt;https://openssl-library.org/news/openssl-3.0-notes/index.html&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CVSS score : CVE-2024-6119, CVE-2024-5535&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This is an already reported issue and there are plans to update the Open SSL libraries in future Qlik Sense releases but we don't have ETA on this. I know this is an inconvenience for you but please watch out for our release notes to identify if the libraries are updated by tracking directly on our Community Page, kindly subscribe to receive notifications on the latest release notes for patches and news releases.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes" target="_blank"&gt;https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/td-p/2480937" target="_blank"&gt;https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/td-p/2480937&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You may need to plan on upgrading your Qlik Sense since it appears the patch will be in later versions of 2025.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 18:12:26 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/m-p/2517987#M31920</guid>
      <dc:creator>vmahmomo</dc:creator>
      <dc:date>2025-05-15T18:12:26Z</dc:date>
    </item>
  </channel>
</rss>

