<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/ta-p/2506352</link>
    <description>&lt;P&gt;PostgreSQL has identified a vulnerability (&lt;FONT color="#339966"&gt;&lt;STRONG&gt;CVE-2025-1094&lt;/STRONG&gt;&lt;/FONT&gt;) that allows for SQL injection under certain scenarios. For more information, see &lt;A href="https://www.postgresql.org/support/security/CVE-2025-1094/" target="_blank" rel="noopener"&gt;CVE-2025-1094: PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;To allow for quick mitigation of PostgreSQL vulnerabilities, Qlik offers the ability to run and manage your own PostgreSQL instance independently of what Qlik Sense Enterprise on Windows is shipped with.&amp;nbsp;This allows for direct control of your PostgreSQL instance and facilitates maintenance without a dependency on Qlik Sense. Further Database upgrades can then be performed independently and in accordance with your corporate security policy when needed, as long as you remain within the supported PostgreSQL versions.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Recommendations&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Upgrade to Qlik Sense Enterprise on Windows May 2025 IR&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Qlik Sense Enterprise on Windows May 2025 IR includes PostgreSQL &lt;FONT color="#339966"&gt;&lt;STRONG&gt;14.17&lt;/STRONG&gt;&lt;/FONT&gt; in its installer. See the &lt;A href="https://help.qlik.com/en-US/sense-admin/May2025/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Common/system-requirements.htm" target="_blank" rel="noopener"&gt;System Requirements&lt;/A&gt; for details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Upgrade PostgreSQL&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;If you have already installed a standalone PostgreSQL database, or if you have used the Qlik PostgreSQL Installer (QPI) to upgrade and decouple your previously bundled database, then you can upgrade PostgreSQL at any time. This means you control maintenance and can immediately react to potential PostgreSQL security concerns by upgrading to a later service release or a later major version.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;See &lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-How-To-Upgrade-Standalone/ta-p/1712361" target="_blank" rel="noopener"&gt;Qlik Sense Enterprise on Windows: How To Upgrade Standalone PostgreSQL&lt;/A&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;Verify your Qlik Sense Enterprise on Windows version's System Requirements before committing to a PostgreSQL version.&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Unbundle and upgrade PostgreSQL using QPI&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;If you have not yet installed a standalone PostgreSQL instance, this is the preferred method to gain&amp;nbsp;&lt;SPAN&gt;direct control to upgrade at your own pace. For instructions, see &lt;/SPAN&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://community.qlik.com/t5/Official-Support-Articles/Upgrading-and-unbundling-the-Qlik-Sense-Repository-Database/ta-p/1934238" target="_blank" rel="noopener"&gt;Upgrading and unbundling the Qlik Sense Repository Database using the Qlik PostgreSQL Installer&lt;/A&gt;&lt;SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Manually switch to a dedicated PostgreSQL database&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;An alternative method to migrate to a standalone PostgreSQL instance is available in&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-configure-Qlik-Sense-to-use-a-dedicated-PostgreSQL/ta-p/1791775" target="_blank" rel="noopener"&gt;How to configure Qlik Sense to use a dedicated PostgreSQL database&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Related Content&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Common/system-requirements.htm" target="_blank" rel="noopener"&gt;System requirements for Qlik Sense Enterprise&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-How-To-Upgrade-Standalone/ta-p/1712361" target="_blank" rel="noopener"&gt;Qlik Sense Enterprise on Windows: How To Upgrade Standalone PostgreSQL&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Upgrading-and-unbundling-the-Qlik-Sense-Repository-Database/ta-p/1934238" target="_blank" rel="noopener"&gt;Upgrading and unbundling the Qlik Sense Repository Database using the Qlik PostgreSQL Installer&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-configure-Qlik-Sense-to-use-a-dedicated-PostgreSQL/ta-p/1791775" target="_blank" rel="noopener"&gt;How to configure Qlik Sense to use a dedicated PostgreSQL database&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Internal Investigation ID(s)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;SUPPORT-896&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise on Windows&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 08 May 2025 14:11:44 GMT</pubDate>
    <dc:creator>Nick_Asilo</dc:creator>
    <dc:date>2025-05-08T14:11:44Z</dc:date>
    <item>
      <title>Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/ta-p/2506352</link>
      <description>&lt;P&gt;PostgreSQL has identified a vulnerability (&lt;FONT color="#339966"&gt;&lt;STRONG&gt;CVE-2025-1094&lt;/STRONG&gt;&lt;/FONT&gt;) that allows for SQL injection under certain scenarios. For more information, see &lt;A href="https://www.postgresql.org/support/security/CVE-2025-1094/" target="_blank" rel="noopener"&gt;CVE-2025-1094: PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;To allow for quick mitigation of PostgreSQL vulnerabilities, Qlik offers the ability to run and manage your own PostgreSQL instance independently of what Qlik Sense Enterprise on Windows is shipped with.&amp;nbsp;This allows for direct control of your PostgreSQL instance and facilitates maintenance without a dependency on Qlik Sense. Further Database upgrades can then be performed independently and in accordance with your corporate security policy when needed, as long as you remain within the supported PostgreSQL versions.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Recommendations&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Upgrade to Qlik Sense Enterprise on Windows May 2025 IR&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Qlik Sense Enterprise on Windows May 2025 IR includes PostgreSQL &lt;FONT color="#339966"&gt;&lt;STRONG&gt;14.17&lt;/STRONG&gt;&lt;/FONT&gt; in its installer. See the &lt;A href="https://help.qlik.com/en-US/sense-admin/May2025/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Common/system-requirements.htm" target="_blank" rel="noopener"&gt;System Requirements&lt;/A&gt; for details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Upgrade PostgreSQL&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;If you have already installed a standalone PostgreSQL database, or if you have used the Qlik PostgreSQL Installer (QPI) to upgrade and decouple your previously bundled database, then you can upgrade PostgreSQL at any time. This means you control maintenance and can immediately react to potential PostgreSQL security concerns by upgrading to a later service release or a later major version.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;See &lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-How-To-Upgrade-Standalone/ta-p/1712361" target="_blank" rel="noopener"&gt;Qlik Sense Enterprise on Windows: How To Upgrade Standalone PostgreSQL&lt;/A&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;Verify your Qlik Sense Enterprise on Windows version's System Requirements before committing to a PostgreSQL version.&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Unbundle and upgrade PostgreSQL using QPI&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;If you have not yet installed a standalone PostgreSQL instance, this is the preferred method to gain&amp;nbsp;&lt;SPAN&gt;direct control to upgrade at your own pace. For instructions, see &lt;/SPAN&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://community.qlik.com/t5/Official-Support-Articles/Upgrading-and-unbundling-the-Qlik-Sense-Repository-Database/ta-p/1934238" target="_blank" rel="noopener"&gt;Upgrading and unbundling the Qlik Sense Repository Database using the Qlik PostgreSQL Installer&lt;/A&gt;&lt;SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Manually switch to a dedicated PostgreSQL database&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;An alternative method to migrate to a standalone PostgreSQL instance is available in&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-configure-Qlik-Sense-to-use-a-dedicated-PostgreSQL/ta-p/1791775" target="_blank" rel="noopener"&gt;How to configure Qlik Sense to use a dedicated PostgreSQL database&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Related Content&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Common/system-requirements.htm" target="_blank" rel="noopener"&gt;System requirements for Qlik Sense Enterprise&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-How-To-Upgrade-Standalone/ta-p/1712361" target="_blank" rel="noopener"&gt;Qlik Sense Enterprise on Windows: How To Upgrade Standalone PostgreSQL&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Upgrading-and-unbundling-the-Qlik-Sense-Repository-Database/ta-p/1934238" target="_blank" rel="noopener"&gt;Upgrading and unbundling the Qlik Sense Repository Database using the Qlik PostgreSQL Installer&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-configure-Qlik-Sense-to-use-a-dedicated-PostgreSQL/ta-p/1791775" target="_blank" rel="noopener"&gt;How to configure Qlik Sense to use a dedicated PostgreSQL database&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Internal Investigation ID(s)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;SUPPORT-896&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise on Windows&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 08 May 2025 14:11:44 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/ta-p/2506352</guid>
      <dc:creator>Nick_Asilo</dc:creator>
      <dc:date>2025-05-08T14:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507316#M15429</link>
      <description>&lt;P&gt;Good day.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I went through your article as well as logging a support call but how can we do the above if you are unable to unbundle the Repository Database? QPI does not run if your database is already on 14.8 especially with clients that has been installed recently as well as new clients.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will it be possible to provide guidance for databases that is unable to use QPI?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 05:52:15 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507316#M15429</guid>
      <dc:creator>Stephanus</dc:creator>
      <dc:date>2025-02-26T05:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507323#M15430</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/197050"&gt;@Stephanus&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this help?&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-manually-upgrade-the-bundled-Qlik-Sense-PostgreSQL/ta-p/1820358" target="_blank" rel="noopener"&gt;How to manually upgrade the bundled Qlik Sense PostgreSQL version&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 07:18:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507323#M15430</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2025-02-26T07:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507350#M15438</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out to me.&lt;/P&gt;
&lt;P&gt;The article that you provided does not show a way to upgrade the bundled version using a higher version than 14.8. The article above is referring to that version having the vulnerability.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The above is one of the scenarios that I have tested and you are still unable to upgrade 14.8 - 14.17 as it is still bundled and requires to be unbundled for the upgrade to occur in Postgres. Qlik November 2024 is still bundled with Postgres 14.8. I haven`t tested Feb 2025 as it is not out yet.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 09:59:35 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507350#M15438</guid>
      <dc:creator>Stephanus</dc:creator>
      <dc:date>2025-02-26T09:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507366#M15439</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/197050"&gt;@Stephanus&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me reach out to my subject matter experts!&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 11:55:30 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507366#M15439</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2025-02-26T11:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507390#M15440</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/197050"&gt;@Stephanus&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your feedback! This was helpful since it allowed me to clarify the article better. And, yes, I did link the wrong article to you on the first pass. I misunderstood the request.&lt;/P&gt;
&lt;P&gt;So, here is what your path should look like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You first need to switch to a standalone PostgreSQL instance. Now, if you cannot use QPI, the second method listed is what we have available:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-configure-Qlik-Sense-to-use-a-dedicated-PostgreSQL/ta-p/1791775" target="_blank" rel="noopener"&gt;How to configure Qlik Sense to use a dedicated PostgreSQL database&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;And from there on out you can continue with upgrading at your leisure:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-How-To-Upgrade-Standalone/ta-p/1712361" target="_blank" rel="noopener"&gt;Qlik Sense Enterprise on Windows: How To Upgrade Standalone PostgreSQL&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 13:31:15 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507390#M15440</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2025-02-26T13:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507420#M15441</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am hoping that you can assist me with a question.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Postgres is part of Qlik, which is installed on our servers behind the Azure firewall. This vulnerability relates to Postgres which is installed on the Qlik server, as mentioned. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Our main question is whether this vulnerability can be exploited via the Qlik frontend, which we have exposed to the internet through port 443 for our customers to be able to access the dashboards, or if it applies only to customers who will have PostgreSQL publicly accessible?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 14:54:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507420#M15441</guid>
      <dc:creator>Marco-Silva</dc:creator>
      <dc:date>2025-02-26T14:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507437#M15443</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/257691"&gt;@Marco-Silva&lt;/a&gt;&amp;nbsp;our security team is still assessing this vulnerability and has not released any public statements or decisions at the time of this post. You can find details of the vulnerability posted by Postgres &lt;A href="https://www.postgresql.org/support/security/CVE-2025-1094/" target="_blank" rel="noopener"&gt;here&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Limiting access to the backend is always the first step in security, though this again only limits access and does not resolve the vulnerability. There has been no confirmation that this vulnerability is exploitable through port 443, but as stated this is still being assessed and I would advise taking the steps above to adopt the released fix and remove any chance&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;Nick&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 15:35:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507437#M15443</guid>
      <dc:creator>Nick_Asilo</dc:creator>
      <dc:date>2025-02-26T15:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507542#M15453</link>
      <description>&lt;P&gt;Hi Sonja&lt;/P&gt;
&lt;P&gt;Thank you very much for the articles and this will be very insightful.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 08:12:13 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507542#M15453</guid>
      <dc:creator>Stephanus</dc:creator>
      <dc:date>2025-02-27T08:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507980#M15468</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;will the bundled PostgreSQL Version be updated or patched via the regular QlikSense Updates at some point and if so, is there a timeline?&amp;nbsp; We would like to keep the bundled version.&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 08:39:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2507980#M15468</guid>
      <dc:creator>oehmemat</dc:creator>
      <dc:date>2025-03-03T08:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2508755#M15498</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see that Feb 2025 is out. Does that installer still have Postgres 14.8 embedded?&lt;/P&gt;
&lt;P&gt;If so it does mean that the new installer has the vulnerability embedded already which can cause an issue for new installs as the QPI does not works with version Nov 2023 or later&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 10:18:45 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2508755#M15498</guid>
      <dc:creator>Stephanus</dc:creator>
      <dc:date>2025-03-07T10:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2508801#M15502</link>
      <description>&lt;P&gt;The QPI toll is not the only way to unbundle the database, as pointed out previously&lt;SPAN&gt;, if you cannot use QPI, the second method listed is what we have available:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-configure-Qlik-Sense-to-use-a-dedicated-PostgreSQL/ta-p/1791775" target="_blank" rel="noopener"&gt;How to configure Qlik Sense to use a dedicated PostgreSQL database&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 13:35:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2508801#M15502</guid>
      <dc:creator>Nick_Asilo</dc:creator>
      <dc:date>2025-03-07T13:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2508805#M15503</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/197050"&gt;@Stephanus&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Qlik Sense Enterprise on Windows has a release cadence of May and November. See &lt;A href="https://community.qlik.com/t5/Support-Updates/Release-Cadence-Update-Qlik-Sense-Enterprise-Client-Managed/ba-p/2430902" target="_blank" rel="noopener"&gt;Release Cadence Update: Qlik Sense Enterprise Client-Managed&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;As for what versions of PostgreSQL come bundled, you will be able to see this in the&amp;nbsp;&lt;EM&gt;System Requirements&amp;nbsp;&lt;/EM&gt;for the relevant release.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 14:38:12 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2508805#M15503</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2025-03-07T14:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2517141#M15760</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/1088"&gt;@oehmemat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May 2025 IR was released yesterday. It includes PostgreSQL 14.17. See the &lt;A href="https://help.qlik.com/en-US/sense-admin/May2025/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/Common/system-requirements.htm" target="_blank" rel="noopener"&gt;System Requirements&lt;/A&gt; for details.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 13:45:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2517141#M15760</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2025-05-08T13:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows and the PostgreSQL CVE-2025-1094 vulnerability</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2544538#M16929</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im running on QlikSense Feb2024 with Patch 17 on single node with postgreSQL 14.17.&lt;/P&gt;&lt;P&gt;Recently my cybersec team detection for the vulnerable on&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;PostgreSQL Multiple Security Vulnerabilities (CVE-2025-8713,CVE-2025-8714,CVE-2025-8715)"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The advice given is to upgrade to the latest version, when tested in the Non-prod environment for postgreSQL 14.19 manually. QlikSense seems not working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will upgrade the QlikSense to the May2025 solving the vulnerability test ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Amir&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 07:34:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-and-the-PostgreSQL-CVE-2025/tac-p/2544538#M16929</guid>
      <dc:creator>sten_still</dc:creator>
      <dc:date>2026-03-11T07:34:51Z</dc:date>
    </item>
  </channel>
</rss>

