<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Product Security and Vulnerability Policy in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/ta-p/1713629</link>
    <description>&lt;P&gt;&lt;FONT size="4" color="#339966"&gt;&lt;STRONG&gt;Does Qlik have a defined security policy?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Qlik takes product security seriously. We have a dedicated team of security experts working on testing, hardening and securing our products. &amp;nbsp;We also work closely with external security companies, our customers and partners to ensure the security of our products is of the highest standard. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Our &lt;A href="https://www.qlik.com/us/trust" target="_blank" rel="noopener"&gt;Qlik Trust and Compliance Center&lt;/A&gt; provides details for compliance and security questions across all Qlik products.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4" color="#339966"&gt;&lt;STRONG&gt;What do I do if I find a security vulnerability in a Qlik product?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Please report any security vulnerability concerns to &lt;A href="https://community.qlik.com/t5/support/ct-p/qlikSupport?launchChat=1" target="_blank" rel="noopener"&gt;Qlik Support&lt;/A&gt;. For an accurate and detailed evaluation of a potential security vulnerability, it is important to clearly describe the scenario in which a vulnerability has been exposed. This includes describing the steps for how security is compromised and what details can be exposed by an attacker.&lt;BR /&gt;&lt;BR /&gt;Notice that generic test reports from 3rd auditing tools typically do not include detailed steps of vulnerability exposure in their security report. These reports commonly refer to potential risk-based patterns; they do not actually expose a vulnerability as part of their system evaluation. Consequently, this means that the default report details are not enough for Qlik to take any immediate action based on the raised concern. Please consult a third-party security auditor or local security expert for complete test case details before reporting a support case with Qlik.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To enable qualified and efficient investigation and action by Qlik, please report each vulnerability concern as an individual support case with Qlik Support. This means that each concern raised in a 3rd party test report must be reported as a separate support case.&lt;BR /&gt;&lt;BR /&gt;For each case, consider adding as much detail as possible, in line with the following items:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik product name&lt;/LI&gt;
&lt;LI&gt;Qlik product version&lt;/LI&gt;
&lt;LI&gt;Test case subject/name (if based on test report)&lt;/LI&gt;
&lt;LI&gt;Complete penetration test report (attach full report for reference)&lt;/LI&gt;
&lt;LI&gt;Name of the security tool used for testing&lt;/LI&gt;
&lt;LI&gt;Details of how to replicate the vulnerability
&lt;UL&gt;
&lt;LI&gt;Step-by-step description of how to expose a vulnerability&lt;/LI&gt;
&lt;LI&gt;Recording of reproduction&lt;/LI&gt;
&lt;LI&gt;Supporting material, such as logs,&amp;nbsp;traffic traces, or screenshots&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Vulnerability impact
&lt;UL&gt;
&lt;LI&gt;Type of information exposed&lt;/LI&gt;
&lt;LI&gt;Unauthorized access to content&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;CVSS score if one is provided by a security auditor&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;CWE (Common Weakness Enumeration) classification, if one is provided&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 09 Oct 2025 12:21:29 GMT</pubDate>
    <dc:creator>Sonja_Bauernfeind</dc:creator>
    <dc:date>2025-10-09T12:21:29Z</dc:date>
    <item>
      <title>Qlik Product Security and Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/ta-p/1713629</link>
      <description>&lt;P&gt;&lt;FONT size="4" color="#339966"&gt;&lt;STRONG&gt;Does Qlik have a defined security policy?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Qlik takes product security seriously. We have a dedicated team of security experts working on testing, hardening and securing our products. &amp;nbsp;We also work closely with external security companies, our customers and partners to ensure the security of our products is of the highest standard. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Our &lt;A href="https://www.qlik.com/us/trust" target="_blank" rel="noopener"&gt;Qlik Trust and Compliance Center&lt;/A&gt; provides details for compliance and security questions across all Qlik products.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4" color="#339966"&gt;&lt;STRONG&gt;What do I do if I find a security vulnerability in a Qlik product?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Please report any security vulnerability concerns to &lt;A href="https://community.qlik.com/t5/support/ct-p/qlikSupport?launchChat=1" target="_blank" rel="noopener"&gt;Qlik Support&lt;/A&gt;. For an accurate and detailed evaluation of a potential security vulnerability, it is important to clearly describe the scenario in which a vulnerability has been exposed. This includes describing the steps for how security is compromised and what details can be exposed by an attacker.&lt;BR /&gt;&lt;BR /&gt;Notice that generic test reports from 3rd auditing tools typically do not include detailed steps of vulnerability exposure in their security report. These reports commonly refer to potential risk-based patterns; they do not actually expose a vulnerability as part of their system evaluation. Consequently, this means that the default report details are not enough for Qlik to take any immediate action based on the raised concern. Please consult a third-party security auditor or local security expert for complete test case details before reporting a support case with Qlik.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To enable qualified and efficient investigation and action by Qlik, please report each vulnerability concern as an individual support case with Qlik Support. This means that each concern raised in a 3rd party test report must be reported as a separate support case.&lt;BR /&gt;&lt;BR /&gt;For each case, consider adding as much detail as possible, in line with the following items:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik product name&lt;/LI&gt;
&lt;LI&gt;Qlik product version&lt;/LI&gt;
&lt;LI&gt;Test case subject/name (if based on test report)&lt;/LI&gt;
&lt;LI&gt;Complete penetration test report (attach full report for reference)&lt;/LI&gt;
&lt;LI&gt;Name of the security tool used for testing&lt;/LI&gt;
&lt;LI&gt;Details of how to replicate the vulnerability
&lt;UL&gt;
&lt;LI&gt;Step-by-step description of how to expose a vulnerability&lt;/LI&gt;
&lt;LI&gt;Recording of reproduction&lt;/LI&gt;
&lt;LI&gt;Supporting material, such as logs,&amp;nbsp;traffic traces, or screenshots&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Vulnerability impact
&lt;UL&gt;
&lt;LI&gt;Type of information exposed&lt;/LI&gt;
&lt;LI&gt;Unauthorized access to content&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;CVSS score if one is provided by a security auditor&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;CWE (Common Weakness Enumeration) classification, if one is provided&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 09 Oct 2025 12:21:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/ta-p/1713629</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2025-10-09T12:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Security Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2031618#M8261</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks for your interesting post about Qlik's security policy! As stated in your post, Qlik takes security seriously and have invested in a dedicated team of security experts and have external security companies at their side. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 14:57:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2031618#M8261</guid>
      <dc:creator>RufusKirk</dc:creator>
      <dc:date>2023-01-30T14:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Security Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2031622#M8262</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Great post on Qlik's security policy and how to handle potential vulnerabilities. It's always important for companies to have dedicated teams and resources in place to ensure the security of their products.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 15:01:09 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2031622#M8262</guid>
      <dc:creator>MeganBriggs</dc:creator>
      <dc:date>2023-01-30T15:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Security Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2101802#M9828</link>
      <description>&lt;P&gt;If Qlik finds a security vulnerability in one of their products, how are customers notified?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 20:44:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2101802#M9828</guid>
      <dc:creator>Ken_T</dc:creator>
      <dc:date>2023-08-02T20:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Security Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2101905#M9831</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/92536"&gt;@Ken_T&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll get back to you on this question.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 06:47:01 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2101905#M9831</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2023-08-03T06:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Security Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2114224#M10084</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the meantime, is there an update on the question posed by &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/92536"&gt;@Ken_T&lt;/a&gt;&amp;nbsp;"&lt;SPAN&gt;If Qlik finds a security vulnerability in one of their products, how are customers notified?"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 18:04:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2114224#M10084</guid>
      <dc:creator>ppmc_united</dc:creator>
      <dc:date>2023-09-06T18:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Security Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2117821#M10183</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/59667"&gt;@ppmc_united&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/92536"&gt;@Ken_T&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For security-related incidents, Qlik follows a Responsible Disclosure approach for any vulnerability that rates as High or Critical by our Software Security Office.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ui-provider eo but bum buu buv buw bux buy buz bva bvb bvc bvd bve bvf bvg bvh bvi bvj bvk bvl bvm bvn bvo bvp bvq bvr bvs bvt bvu bvv bvw bvx bvy bvz"&gt;This approach includes publishing a Security Bulletin to alert our customers and partners through a blog post&lt;/SPAN&gt;&lt;SPAN&gt;, collaborating with the reporter of the vulnerability if applicable, creating software fixes as soon as possible, and/or providing mitigation until fixed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional methods are being investigated, but no details or timeframe can be given at this point.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:11:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2117821#M10183</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2023-09-18T11:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Product Security and Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2522103#M15987</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;As a result of the customer's security team's checks, CVE-2025-32433 Erlang / OTP was found on the server where Nprinting was installed last week. But now we are faced with a new vulnerability code. We could not find any information or documentation about it.&lt;/P&gt;&lt;P&gt;Old vulnerability code: CVE-2025-32433&lt;BR /&gt;New vulnerability code: CVE-2025-4748&lt;/P&gt;&lt;P&gt;The customer is using the February 2024 SR3 NPrinting version. Which version fixes this vulnerability?&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;I opened a case with Qlik Support but they said that if I contact you through this article, an engineer will be assigned to this case and you can contact me for further technical assistance.&lt;/U&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArmaganYali_0-1750763239143.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/181576i701CBD0CAA7D7FBF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ArmaganYali_0-1750763239143.png" alt="ArmaganYali_0-1750763239143.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArmaganYali_1-1750763239210.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/181577iC953110557EBB79A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ArmaganYali_1-1750763239210.png" alt="ArmaganYali_1-1750763239210.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Armağan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 11:16:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2522103#M15987</guid>
      <dc:creator>ArmaganYali</dc:creator>
      <dc:date>2025-06-24T11:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Product Security and Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2522108#M15988</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/303679"&gt;@ArmaganYali&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe this is misunderstood.&lt;/P&gt;
&lt;P&gt;This article is for your reference, not meant to be where you get support. It is meant to give you more information and let you know what sort of information you need to send to support. An engineer will work with you on the case directly. Please communicate with the engineer directly in your case. From what I can see it has already been assigned.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 11:28:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2522108#M15988</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2025-06-24T11:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Product Security and Vulnerability Policy</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2522122#M15991</link>
      <description>&lt;P&gt;Ok,&amp;nbsp;I probably misunderstood.&lt;BR /&gt;Thank you&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 12:26:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Product-Security-and-Vulnerability-Policy/tac-p/2522122#M15991</guid>
      <dc:creator>ArmaganYali</dc:creator>
      <dc:date>2025-06-24T12:26:49Z</dc:date>
    </item>
  </channel>
</rss>

