<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump) in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/ta-p/2497033</link>
    <description>&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Affected versions:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;Qlik Sense Enterprise on Windows all versions, including November 2024&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;CVE-2024-7348&lt;/STRONG&gt;&lt;/FONT&gt; is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in &lt;FONT color="#339966"&gt;&lt;STRONG&gt;pg_dump&lt;/STRONG&gt;&lt;/FONT&gt;, a utility used for backing up PostgreSQL databases. This vulnerability allows an attacker to replace a relation type (such as a table or sequence) with a view or foreign table right when pg_dump is running. Because pg_dump often runs with superuser privileges, this attack could execute arbitrary SQL code, leading to unauthorized actions or data corruption. Source:&amp;nbsp;&lt;A href="https://www.postgresql.org/support/security/CVE-2024-7348/" target="_blank" rel="noopener"&gt;https://www.postgresql.org/support/security/CVE-2024-7348/&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;How does this vulnerability impact Qlik Sense Enterprise on Windows?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Qlik can confirm that &lt;FONT color="#339966"&gt;&lt;STRONG&gt;pg_dump&lt;/STRONG&gt;&lt;/FONT&gt; &lt;STRONG&gt;&lt;FONT color="#339966"&gt;is&lt;/FONT&gt; &lt;FONT color="#339966"&gt;not actively used in the Qlik Sense Enterprise on Windows code&lt;/FONT&gt;&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;How to mitigate the vulnerability&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4 id="toc-hId-966858635"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Upgrade to Qlik Sense Enterprise on Windows May 2025 IR&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Qlik Sense Enterprise on Windows May 2025 IR includes PostgreSQL&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;14.17&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in its installer. See the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/May2025/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Common/system-requirements.htm" target="_blank" rel="noopener nofollow noreferrer" aria-describedby="audioeye_new_window_message"&gt;System Requirements&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for details.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;If upgrading Qlik Sense is not possible, manually upgrade PostgreSQL&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Both steps are required to fully mitigate the issue.&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;Upgrade PostgreSQL. This requires a standalone instance of PostgreSQL. See &lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Upgrading-and-unbundling-the-Qlik-Sense-Repository-Database/ta-p/1934238" target="_blank" rel="noopener" data-lightning-target="_new"&gt;Upgrading and unbundling the Qlik Sense Repository Database using the Qlik PostgreSQL Installer&lt;/A&gt; on how to unbundle PostgreSQL if necessary.
&lt;BLOCKQUOTE class="quote"&gt;Always verify compatibility between your Qlik Sense version and PostgreSQL before planning an upgrade.&lt;/BLOCKQUOTE&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Delete the &lt;EM&gt;pg_dump.exe &lt;/EM&gt;located in the default Qlik Sense&lt;/SPAN&gt; Enterprise on Windows Postgresql install folder: &lt;EM&gt;C:\Program Files\Qlik\Sense\Repository\Postgresql\14\&lt;BR /&gt;&lt;/EM&gt;
&lt;BLOCKQUOTE class="quote"&gt;The file will be recreated after an upgrade. This step will need to be repeated after each Qlik Sense upgrade.&amp;nbsp;&lt;SPAN&gt;Qlik is actively investigating the removal of pg_dump from future installers (SHEND-2041).&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;
The updated pg_dump.exe in, for example, &lt;SPAN&gt;&lt;EM&gt;C:\program files\postgresql\14&lt;/EM&gt; does not need to be removed.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Does the Qlik PostgreSQL Installer (QPI) use the pgdump.exe?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;QPI does not utilise&amp;nbsp;&lt;EM&gt;pgdump.exe.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Internal Investigation ID(s)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;QB-28706&lt;/LI&gt;
&lt;LI&gt;SHEND-2041&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Fri, 09 May 2025 10:55:01 GMT</pubDate>
    <dc:creator>Sebastian_Linser</dc:creator>
    <dc:date>2025-05-09T10:55:01Z</dc:date>
    <item>
      <title>Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/ta-p/2497033</link>
      <description>&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Affected versions:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI class="lia-indent-padding-left-30px"&gt;Qlik Sense Enterprise on Windows all versions, including November 2024&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;CVE-2024-7348&lt;/STRONG&gt;&lt;/FONT&gt; is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in &lt;FONT color="#339966"&gt;&lt;STRONG&gt;pg_dump&lt;/STRONG&gt;&lt;/FONT&gt;, a utility used for backing up PostgreSQL databases. This vulnerability allows an attacker to replace a relation type (such as a table or sequence) with a view or foreign table right when pg_dump is running. Because pg_dump often runs with superuser privileges, this attack could execute arbitrary SQL code, leading to unauthorized actions or data corruption. Source:&amp;nbsp;&lt;A href="https://www.postgresql.org/support/security/CVE-2024-7348/" target="_blank" rel="noopener"&gt;https://www.postgresql.org/support/security/CVE-2024-7348/&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;How does this vulnerability impact Qlik Sense Enterprise on Windows?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Qlik can confirm that &lt;FONT color="#339966"&gt;&lt;STRONG&gt;pg_dump&lt;/STRONG&gt;&lt;/FONT&gt; &lt;STRONG&gt;&lt;FONT color="#339966"&gt;is&lt;/FONT&gt; &lt;FONT color="#339966"&gt;not actively used in the Qlik Sense Enterprise on Windows code&lt;/FONT&gt;&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;How to mitigate the vulnerability&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4 id="toc-hId-966858635"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Upgrade to Qlik Sense Enterprise on Windows May 2025 IR&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Qlik Sense Enterprise on Windows May 2025 IR includes PostgreSQL&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;14.17&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in its installer. See the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/May2025/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Common/system-requirements.htm" target="_blank" rel="noopener nofollow noreferrer" aria-describedby="audioeye_new_window_message"&gt;System Requirements&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for details.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;If upgrading Qlik Sense is not possible, manually upgrade PostgreSQL&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Both steps are required to fully mitigate the issue.&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;Upgrade PostgreSQL. This requires a standalone instance of PostgreSQL. See &lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Upgrading-and-unbundling-the-Qlik-Sense-Repository-Database/ta-p/1934238" target="_blank" rel="noopener" data-lightning-target="_new"&gt;Upgrading and unbundling the Qlik Sense Repository Database using the Qlik PostgreSQL Installer&lt;/A&gt; on how to unbundle PostgreSQL if necessary.
&lt;BLOCKQUOTE class="quote"&gt;Always verify compatibility between your Qlik Sense version and PostgreSQL before planning an upgrade.&lt;/BLOCKQUOTE&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Delete the &lt;EM&gt;pg_dump.exe &lt;/EM&gt;located in the default Qlik Sense&lt;/SPAN&gt; Enterprise on Windows Postgresql install folder: &lt;EM&gt;C:\Program Files\Qlik\Sense\Repository\Postgresql\14\&lt;BR /&gt;&lt;/EM&gt;
&lt;BLOCKQUOTE class="quote"&gt;The file will be recreated after an upgrade. This step will need to be repeated after each Qlik Sense upgrade.&amp;nbsp;&lt;SPAN&gt;Qlik is actively investigating the removal of pg_dump from future installers (SHEND-2041).&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;
The updated pg_dump.exe in, for example, &lt;SPAN&gt;&lt;EM&gt;C:\program files\postgresql\14&lt;/EM&gt; does not need to be removed.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Does the Qlik PostgreSQL Installer (QPI) use the pgdump.exe?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;QPI does not utilise&amp;nbsp;&lt;EM&gt;pgdump.exe.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Internal Investigation ID(s)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;QB-28706&lt;/LI&gt;
&lt;LI&gt;SHEND-2041&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 09 May 2025 10:55:01 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/ta-p/2497033</guid>
      <dc:creator>Sebastian_Linser</dc:creator>
      <dc:date>2025-05-09T10:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2497293#M15085</link>
      <description>&lt;P&gt;The link under &lt;A href="https://community.qlik.com/articles/Knowledge/Upgrading-and-unbundling-the-Qlik-Sense-Repository-Database-using-the-Qlik-PostgreSQL-Installer" target="_blank" rel="noopener" data-lightning-target="_new"&gt;Upgrading and unbundling the Qlik Sense Repository Database using the Qlik PostgreSQL Installer&lt;/A&gt; does not work.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 08:12:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2497293#M15085</guid>
      <dc:creator>dennemanr</dc:creator>
      <dc:date>2024-12-11T08:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2497299#M15086</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/24313"&gt;@dennemanr&lt;/a&gt;&amp;nbsp;Fixed!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 08:38:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2497299#M15086</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-12-11T08:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2498467#M15128</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/19162"&gt;@Sebastian_Linser&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;The updated pg_dump.exe in, for example, C:\program files\postgresql\14 does not need to be removed.&lt;/P&gt;
&lt;P&gt;Regarding the above, am I correct in my understanding that if a fixed version (14.13 or later) is manually installed, it does not need to be removed?&lt;/P&gt;
&lt;P&gt;Also, if I have manually installed PostgresSQL, but I have a version prior to the fixed version, is it correct to recognize that you need to take action?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 07:11:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2498467#M15128</guid>
      <dc:creator>sis</dc:creator>
      <dc:date>2024-12-18T07:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499084#M15145</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/19162"&gt;@Sebastian_Linser&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What is the status of the investigation regarding my question?&lt;BR /&gt;I'm sorry for your inconvenience, but thank you for your response.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 02:36:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499084#M15145</guid>
      <dc:creator>sis</dc:creator>
      <dc:date>2024-12-23T02:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499100#M15150</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/119559"&gt;@sis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both steps are required. Your Standalone PostgreSQL instance will have the file stored (for example) here:&amp;nbsp;&lt;EM&gt;C:\program files\postgresql\14&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;While the Qlik copy of the file is here:&amp;nbsp;&lt;EM&gt;C:\Program Files\Qlik\Sense\Repository\Postgresql\14\&amp;nbsp;&lt;/EM&gt;(this is the one which needs to be deleted as it will be version 14).&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 06:56:16 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499100#M15150</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-12-23T06:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499105#M15151</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for answering my question.&lt;BR /&gt;&lt;BR /&gt;I understand that both steps are required after the PostgreSQL upgrade.&lt;BR /&gt;(I don't delete files stored by a standalone PostgreSQL instance.&lt;BR /&gt;&amp;nbsp;I delete the following files:C:\Program Files\Qlik\Sense\Repository\Postgresql\14)&lt;BR /&gt;&lt;BR /&gt;If I installed fixed version (14.13 or later) before installing Qlik Sense, it doesn't fall under this vulnerability, and therefore no action is required in that case?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 07:43:12 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499105#M15151</guid>
      <dc:creator>sis</dc:creator>
      <dc:date>2024-12-23T07:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499109#M15152</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/119559"&gt;@sis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have forwarded this question. But please note that resources are currently not as readily available and a support case may be the easiest way to keep your question tracked.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 08:01:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499109#M15152</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-12-23T08:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499142#M15153</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/119559"&gt;@sis&lt;/a&gt;&amp;nbsp;To confirm:&lt;/P&gt;
&lt;P&gt;The embedded binaries are always installed. Even if you have, from the start, chosen to use a standalone PostgreSQL instance.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 11:30:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499142#M15153</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-12-23T11:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499193#M15158</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the info.&lt;BR /&gt;&lt;BR /&gt;＞Even if you have, from the start, chosen to use a standalone PostgreSQL instance.&lt;BR /&gt;&lt;BR /&gt;In the above case, in the section 'How to mitigate vulnerabilities' in this article, is it sufficient to just delete the Postgresql installation folder (C:Program FilesQlikSenseRepositoryPostgresql14) without performing an upgrade?&lt;BR /&gt;&lt;BR /&gt;I'm wondering if I can consider the upgrade to be already completed.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 02:20:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499193#M15158</guid>
      <dc:creator>sis</dc:creator>
      <dc:date>2024-12-24T02:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499411#M15166</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/119559"&gt;@sis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is not a question I can answer myself. I will forward this one as well, but as before: resources are currently not as readily available so it may take time before we are able to get back to you.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 07:59:44 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499411#M15166</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-12-27T07:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499439#M15174</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/119559"&gt;@sis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deleting the whole folder is not possible. Only delete the specific file which is not in use.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 12:29:02 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499439#M15174</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-12-27T12:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499448#M15175</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does -&amp;nbsp;&lt;SPAN&gt;Qlik can confirm that&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;pg_dump&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;is&lt;/FONT&gt;&lt;FONT color="#339966"&gt;not actively used in the Qlik Sense Enterprise on Windows code mean?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#339966"&gt;If the Qliksense is installed on windows no need to do anything?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 13:56:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499448#M15175</guid>
      <dc:creator>spalla</dc:creator>
      <dc:date>2024-12-27T13:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499452#M15176</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/174705"&gt;@spalla&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It means the file is not being used by Qlik Sense and can therefore be deleted without affecting the product itself.&lt;/P&gt;
&lt;P&gt;To mitigate the PostgreSQL vulnerability, please follow the mentioned mitigation steps.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja Bauernfeind&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 14:22:42 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499452#M15176</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-12-27T14:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499453#M15177</link>
      <description>&lt;P&gt;Thank you.I get that file needs be deleted but what does it mean by below.&lt;/P&gt;
&lt;P&gt;The updated pg_dump.exe in, for example,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;EM&gt;C:\program files\postgresql\14&lt;/EM&gt;&amp;nbsp;does not need to be removed.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 14:29:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499453#M15177</guid>
      <dc:creator>spalla</dc:creator>
      <dc:date>2024-12-27T14:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499454#M15178</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/174705"&gt;@spalla&lt;/a&gt;&amp;nbsp;Once you have&amp;nbsp;&lt;STRONG&gt;unbundled&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;upgraded&amp;nbsp;&lt;/STRONG&gt;PostgreSQL to a version which includes the fix for the pgdump vulnerability, you will find two copies of pgdump.exe.&lt;/P&gt;
&lt;P&gt;One will be in your Qlik Sense installation directory (example&amp;nbsp;&lt;EM&gt;C:\&lt;STRONG&gt;Program Files\Qlik\Sense\Repository&lt;/STRONG&gt;\Postgresql\x\&lt;/EM&gt;) and will still be the same version as whatever was installed with Qlik Sense. These binaries are always installed with Qlik Sense. This is what you need to delete.&lt;/P&gt;
&lt;P&gt;The second one will be in the location you pointed your&amp;nbsp;standalone PostgreSQL install to (example: &lt;EM&gt;C:\program files\postgresql\x&lt;/EM&gt;).&amp;nbsp;The pgdump.exe in the second location will be whatever version you have just installed, meaning it is no longer vulnerable. You can still delete it, but do not&amp;nbsp;&lt;EM&gt;have&amp;nbsp;&lt;/EM&gt;to.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you choose to &lt;STRONG&gt;skip&lt;/STRONG&gt; the&amp;nbsp;&lt;STRONG&gt;unbundle&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;upgrade&amp;nbsp;&lt;/STRONG&gt;step, you will not have a file in the second location.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 14:44:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2499454#M15178</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-12-27T14:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2500542#M15208</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If I upgrade Qlik Sense Enterprise on Windows after addressing this vulnerability, will the following folders be re-generated?&lt;BR /&gt;&lt;BR /&gt;C:\Program Files\Qlik\Sense\Repository\Postgresql\14\&lt;BR /&gt;&lt;BR /&gt;If the folder is regenerated, do I need to delete the "pg_dump.exe" every time I upgrade Qlik Sense Enterprise on Windows?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 09:23:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2500542#M15208</guid>
      <dc:creator>sis</dc:creator>
      <dc:date>2025-01-09T09:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2500614#M15209</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/119559"&gt;@sis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is correct. I have updated the article accordingly and added our internal investigations for this topic so they an be easily referenced in future Release Notes.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 12:59:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2500614#M15209</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2025-01-09T12:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2503417#M15270</link>
      <description>&lt;P&gt;We have already unbundled our postgres from 12 to 14 and changed the installation path to&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;C:\program files\postgresql\14.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;So we do not have anything folder named as postgres inside default path "&lt;SPAN&gt;C:\Program Files\Qlik\Sense\Repository" so I think we do not need to take any action here as we are already running standalone postgres.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And to answer below question I would say that in our case after upgrading qliksense we didnt see that this folder is regenerated.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tool_Tip_0-1738127848015.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/176998iB619EDC364F6D33C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Tool_Tip_0-1738127848015.png" alt="Tool_Tip_0-1738127848015.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 05:17:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2503417#M15270</guid>
      <dc:creator>Tool_Tip</dc:creator>
      <dc:date>2025-01-29T05:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and PostgreSQL vulnerability CVE-2024-7348 (pg_dump)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2503418#M15271</link>
      <description>&lt;P&gt;Can I conclude this as -&lt;/P&gt;
&lt;P&gt;- Now onwards it is mandatory to use standalone postgres instead of bundled one ?&lt;/P&gt;
&lt;P&gt;- By chance if anyone is getting "&lt;SPAN&gt;C:\Program Files\Qlik\Sense\Repository\Postgresql\14\" this folder is regenerating after any qliksense upgrade activity then it must be deleted due to "&lt;STRONG&gt;CVE-2024-7348" ?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Kindly confirm.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 05:24:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-PostgreSQL-vulnerability/tac-p/2503418#M15271</guid>
      <dc:creator>Tool_Tip</dc:creator>
      <dc:date>2025-01-29T05:24:37Z</dc:date>
    </item>
  </channel>
</rss>

