Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
Independent validation for trusted, AI-ready data integration. See why IDC named Qlik a Leader: Read the Excerpt!
cancel
Showing results for 
Search instead for 
Did you mean: 
BuTbka
Creator II
Creator II

Vulnerabilities OpenSSL 1.1.0

Hello!
There are several outdated OpenSSL libs with vulnerabilities in connector package

BuTbka_0-1726044142026.png
QS May 2024 Patch 5 

Nessus scan results:
[
"OpenSSL Project OpenSSL 1.1.1h (C:\\Program files\\Qlik\\Sense\\Repository\\Postgresql\\12.5\\Bin\\)",
"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Hive\\Lib\\Libcurl64.dlla\\Openssl64.dlla\\)",
"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Hive\\Lib\\Openssl64.dlla\\)",
"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Impala\\Lib\\Openssl64.dlla\\)",
"OpenSSL Project OpenSSL 1.1.1n (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Mysql\\Lib\\Openssl64.dlla\\)",
"OpenSSL Project OpenSSL 1.1.0j (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Phoenix\\Lib\\Openssl64.dlla\\)"
]


Where we can download updated drivers or libs?

Labels (2)
2 Replies
tin_u
Partner - Contributor II
Partner - Contributor II

Have this been addressed by anyone? Patch 11 still has this version on our instances, upgrading to Patch 15 came with the following:

tin_u_0-1743066486981.png

 

vmahmomo
Contributor II
Contributor II

I am also facing the same issue, have opened the ticket with Qlik support and here is the answer i have received.

It seems that Qlik Sense Enterprise has OpenSSL libraries at
C:\program files\common files\qlik\custom data\qvodbcconnectorpackage\...\lib
OpenSSL 3.0.15 has security fixes - https://openssl-library.org/news/openssl-3.0-notes/index.html

CVSS score : CVE-2024-6119, CVE-2024-5535

This is an already reported issue and there are plans to update the Open SSL libraries in future Qlik Sense releases but we don't have ETA on this. I know this is an inconvenience for you but please watch out for our release notes to identify if the libraries are updated by tracking directly on our Community Page, kindly subscribe to receive notifications on the latest release notes for patches and news releases.

https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes
https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/td-p/2480937

You may need to plan on upgrading your Qlik Sense since it appears the patch will be in later versions of 2025.