Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
Save $650 on Qlik Connect, Dec 1 - 7, our lowest price of the year. Register with code CYBERWEEK: Register
cancel
Showing results for 
Search instead for 
Did you mean: 
rbecher
MVP
MVP

QVD/QVW files store connection string in plain text!

Hi all,

I want to mention this thread which describes a serious security issue:

http://community.qlik.com/message/171643

This is happen at least with QV10 SR3.

I would encourage all of you to update to version 10 SR4.

- Ralf

Data & AI Engineer at Orionbelt.ai - a GenAI Semantic Layer Venture, Inventor of Astrato Engine
Labels (3)
4 Replies
rbecher
MVP
MVP
Author

To keep it short, to remove the password:

1. affected QVW files must be opened and saved with QV10 SR4, a reload is not needed

2. affected QVD files must be recreated (stored) with QV10 SR4

- Ralf

Data & AI Engineer at Orionbelt.ai - a GenAI Semantic Layer Venture, Inventor of Astrato Engine
rbecher
MVP
MVP
Author

Web file sources (URLs) are also affected!!

http://community.qlik.com/message/171838#171838

- Ralf

Data & AI Engineer at Orionbelt.ai - a GenAI Semantic Layer Venture, Inventor of Astrato Engine
rbecher
MVP
MVP
Author

Also section access and hidden script is affected!!

http://community.qlik.com/message/172321#172321

- Ralf

Data & AI Engineer at Orionbelt.ai - a GenAI Semantic Layer Venture, Inventor of Astrato Engine
rbecher
MVP
MVP
Author

There will be a fix next week:

http://community.qlik.com/message/174787#174787

- Ralf

Data & AI Engineer at Orionbelt.ai - a GenAI Semantic Layer Venture, Inventor of Astrato Engine