Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 
mj26
Partner - Contributor III
Partner - Contributor III

VAPT Qualys scan on our Qlik reporting server error/findings

Hi Qlik Fam,

Requesting assistance for the error encountered upon conducting a VAPT Qualys scan on our Qlik reporting server, which has shown 3 vulnerable, we would appreciate your insights on the following vulnerable listed below:

1. HTTP Security Header Not Detected
2. Secure Sockets Layer/Transport Layer Security (SSL/TLS) server supports Transport Layer Security (TLSv1.0)
3. TLS Padding Oracle Vulnerability (Zombie POODLE and GOLDENDOODLE)

Thank you in  advance. 

1 Reply
mpc
Partner Ambassador
Partner Ambassador

Hi, 

Please execute IIS Crypto to disable weak cipher suite/TLS protocol: https://www.nartac.com/Products/IISCrypto

Then perform a new scan of your server. 

Kind regards

From Next Decision and mpc with love