<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerabilities found during QlikSense application scan in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-found-during-QlikSense-application-scan/m-p/1876878#M30122</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/160499"&gt;@Pawan_Mahajan&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Can you please raise a case with support directly for this issue an be sure to include all the information as mentioned in the article below&lt;BR /&gt;-&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/Qlik-Security-Vulnerability-Policy/ta-p/1713629" target="_blank"&gt;https://community.qlik.com/t5/Knowledge/Qlik-Security-Vulnerability-Policy/ta-p/1713629&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You can find the steps to raise a case with support here&lt;BR /&gt;-&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/How-to-create-a-case-and-contact-Qlik-Support/ta-p/1710992" target="_blank"&gt;https://community.qlik.com/t5/Knowledge/How-to-create-a-case-and-contact-Qlik-Support/ta-p/1710992&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jan 2022 07:43:07 GMT</pubDate>
    <dc:creator>Seanog_Murphy</dc:creator>
    <dc:date>2022-01-04T07:43:07Z</dc:date>
    <item>
      <title>Vulnerabilities found during QlikSense application scan</title>
      <link>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-found-during-QlikSense-application-scan/m-p/1875596#M30121</link>
      <description>&lt;P&gt;While doing application vulnerabilities scan we found below issues, 1. &lt;STRONG&gt;Session token in url is visible:&lt;/STRONG&gt;- Qlik ticket is visible in qlik application url. 2. &lt;STRONG&gt;Cookies path is not set&lt;/STRONG&gt;:- X-Qlik-Session cookie in virtual proxy. This cookie path is not set to root folder. 3. &lt;STRONG&gt;Etag Version Disclosure&lt;/STRONG&gt;:- etag is visible on qlik application page.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 16:57:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-found-during-QlikSense-application-scan/m-p/1875596#M30121</guid>
      <dc:creator>Pawan_Mahajan</dc:creator>
      <dc:date>2025-01-29T16:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerabilities found during QlikSense application scan</title>
      <link>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-found-during-QlikSense-application-scan/m-p/1876878#M30122</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/160499"&gt;@Pawan_Mahajan&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Can you please raise a case with support directly for this issue an be sure to include all the information as mentioned in the article below&lt;BR /&gt;-&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/Qlik-Security-Vulnerability-Policy/ta-p/1713629" target="_blank"&gt;https://community.qlik.com/t5/Knowledge/Qlik-Security-Vulnerability-Policy/ta-p/1713629&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You can find the steps to raise a case with support here&lt;BR /&gt;-&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/How-to-create-a-case-and-contact-Qlik-Support/ta-p/1710992" target="_blank"&gt;https://community.qlik.com/t5/Knowledge/How-to-create-a-case-and-contact-Qlik-Support/ta-p/1710992&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 07:43:07 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Vulnerabilities-found-during-QlikSense-application-scan/m-p/1876878#M30122</guid>
      <dc:creator>Seanog_Murphy</dc:creator>
      <dc:date>2022-01-04T07:43:07Z</dc:date>
    </item>
  </channel>
</rss>

