<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security issue in the QV PUBLISHER in QlikView</title>
    <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627032#M1301010</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would say it´s a matter of planning and administrate..&lt;/P&gt;&lt;P&gt;As suggested, if someone has access to Administrator account, and put script varibles in load statements, that is not suppose to be done, for security reasons, then I would say that you have to see over your planning for folder security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you could run a batch/vbs script, execute it with a Sales vs Campaign user calling Qv.exe instead of running it with QlikView Distribution Service&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 May 2014 08:15:42 GMT</pubDate>
    <dc:creator />
    <dc:date>2014-05-12T08:15:42Z</dc:date>
    <item>
      <title>security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627024#M1300988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to run QV Publisher tasks under different users.&amp;nbsp; The reason i am asking this is the following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance we have 2 domains : Marketing and Sales.&amp;nbsp; Users from Sales are&lt;BR /&gt;not allowed to access certain Marketing info.&amp;nbsp; But as a consequence of the&lt;BR /&gt;fact that all the Publisher tasks run with the same user, there is no&lt;BR /&gt;possibility to do this.&amp;nbsp; Actually, if the sales people know the name and&lt;BR /&gt;location of the Marketing data, they can use this path in their script and&lt;BR /&gt;schedule it in the publisher.&amp;nbsp; The publisher runs this task with the&lt;BR /&gt;global machine user, which runs also tasks for finance, and has access to as&lt;BR /&gt;well the Sales as the marketing data.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;This seems to be a security leak to me, because in this way users can see data, they are not allowed to!&lt;/P&gt;&lt;P&gt;&amp;nbsp; Is there any solution for this or am i working in a wrong way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2026 18:19:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627024#M1300988</guid>
      <dc:creator />
      <dc:date>2026-01-26T18:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627025#M1300991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why should the users other than the QlikView Administrators have access to the QMC to reschedule Publisher tasks?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 13:35:25 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627025#M1300991</guid>
      <dc:creator>simondachstr</dc:creator>
      <dc:date>2014-05-08T13:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627026#M1300995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if it is the Qlmikview admin, also then it doesn't seem normal to me that a task scheduled for Sales can access any Marketing data, even if Sales has no rights to this data&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your quick reply&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 13:39:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627026#M1300995</guid>
      <dc:creator />
      <dc:date>2014-05-08T13:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627027#M1301000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A task does not have access to data - a QlikView Application has. The task simply reloads and if necessary distributes/publishes the qvw file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you aware of the Section Access feature with the "Initial data reduction based on section access" option? I believe this should cover your concerns.. Attached you can find a useful introduction section access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 13:49:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627027#M1301000</guid>
      <dc:creator>simondachstr</dc:creator>
      <dc:date>2014-05-08T13:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627028#M1301004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok the task simply reloads, but imagine that we have 3 users :&lt;/P&gt;&lt;P&gt;AdminU (=the Qlikview Admin user who runs the tasks)&lt;/P&gt;&lt;P&gt;SalesU (=A user from sales)&lt;/P&gt;&lt;P&gt;MarkU (= User from Marketing)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AdminU as QV admin has rigths to ProductsSold.qvd AND Campaigns.qvd&lt;/P&gt;&lt;P&gt;SalesU only to ProductsSold.qvd&lt;/P&gt;&lt;P&gt;MarkU only to Campaigns.qvd&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, considering the script below ... if we run this script with user AdminU, then we are able to access Campaigns.qvd, even if this application was built by SalesU :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Sales:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style=": ; color: #0000ff; font-size: 8pt;"&gt;LOAD&lt;/STRONG&gt;&lt;SPAN style="font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp; * &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;FROM&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;C&gt; (&lt;/C&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;qvd&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;); &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Marketing:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style=": ; color: #0000ff; font-size: 8pt;"&gt;LOAD&lt;/STRONG&gt;&lt;SPAN style="font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp; * &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;FROM&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;C&gt; (&lt;/C&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;qvd&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;); &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 14:05:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627028#M1301004</guid>
      <dc:creator />
      <dc:date>2014-05-08T14:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627029#M1301006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following sentence confuses me:&lt;/P&gt;&lt;P&gt;On the one hand you are saying "AdminU as QV admin has rigths to ProductsSold.qvd AND Campaigns.qvd" and on the other hand it suprises you "if we run this script with user AdminU, then we are able to access Campaigns.qvd, even if this application was built by SalesU".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you considered working with Folder security instead?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 15:06:27 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627029#M1301006</guid>
      <dc:creator>simondachstr</dc:creator>
      <dc:date>2014-05-08T15:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627030#M1301008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we use AdminU as QDS-account (QDS : Qlikview Distribution Service), then we MUST give AdminU access to both QVDs because he runs tasks as wel for Sales as for Marketing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that's the whole problem.&amp;nbsp; SalesU can put this in his script :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Marketing:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #0000ff; font-size: 8pt;"&gt;LOAD&lt;/STRONG&gt;&lt;SPAN style="font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp; * &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;FROM&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;C&gt; (&lt;/C&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;qvd&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;);&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;And although he does not have access to this data, he will be able to retrieve the data because the job in the publisher is executed by the AdminU account.&amp;nbsp; That's my question, can we run scheduled tasks at night on a server (via the publisher) with the rigths of the user who created this task instead of that 1 user who executes all the tasks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 15:16:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627030#M1301008</guid>
      <dc:creator />
      <dc:date>2014-05-08T15:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627031#M1301009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;You can use NTFS security, so even if&amp;nbsp; for example a Marketing user tries to reload info taken from a Sales QVD, he won't be able to do it. Also you may want to give it a check to &lt;A href="https://community.qlik.com/group/1224"&gt;QlikView Deployment Framework&lt;/A&gt; which is a group where you can find documentation of how to deploy QlikView in an enterprise environment,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 16:03:16 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627031#M1301009</guid>
      <dc:creator>jaimeaguilar</dc:creator>
      <dc:date>2014-05-08T16:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627032#M1301010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would say it´s a matter of planning and administrate..&lt;/P&gt;&lt;P&gt;As suggested, if someone has access to Administrator account, and put script varibles in load statements, that is not suppose to be done, for security reasons, then I would say that you have to see over your planning for folder security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you could run a batch/vbs script, execute it with a Sales vs Campaign user calling Qv.exe instead of running it with QlikView Distribution Service&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 May 2014 08:15:42 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627032#M1301010</guid>
      <dc:creator />
      <dc:date>2014-05-12T08:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627033#M1301011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at the attached. I am sure this will help you on what you want to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 May 2014 11:56:16 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627033#M1301011</guid>
      <dc:creator>Bill_Britt</dc:creator>
      <dc:date>2014-05-12T11:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: security issue in the QV PUBLISHER</title>
      <link>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627034#M1301012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sven - I follow what you are saying.&amp;nbsp; How did you end up handling the situation you described?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Feb 2015 19:59:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/security-issue-in-the-QV-PUBLISHER/m-p/627034#M1301012</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-02-04T19:59:36Z</dc:date>
    </item>
  </channel>
</rss>

