Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
Jan 27, 2022 4:13:15 AM
Dec 13, 2021 3:33:26 PM
Qlik GeoAnalytics Server and the Qlik GeoAnalytics Connector in combination with GeoAnalytics Plus are both affected by the log4j vulnerability.
Patches are available. See Vulnerability Testing - Apache Log4j, reference CVE-2021-44228 (also referred to as Log4Shell) for your release of Qlik GeoAnalytics and the relevant patch.
Upgrade at the earliest.
Mitigation steps are provided below should not upgrade be possible at this time.
The Standard GeoAnalytics Connector for Qlikview and QlikSense (bundled) without GeoAnalytics Plus are not affected by it, they don't use Java.
<add key="javaArgs" value=""/>
<add key="javaArgs" value="-Dlog4j2.formatMsgNoLookups=true"/>
This applies only to GeoAnalytics Plus Connector Version May 2021 and higher.
Versions prior to February 2020 uses Log4j v1, which is not vulnerable to this exploit. To prevent any other possible vulnerabilities, we recommend upgrading to a newer version (higher than May 2021) of GeoAnalytics Plus and then applying the mitigation.
Alternatively, you can manually replace the Log4j library files with newer versions:
For more information on the Log4j vulnerability, please visit the Support Updates Blog post.
As a short update we released:
@KallePersson could you please help to confirm this:
The patch on Download site is for GA Nov 21 release. For the earlier version, for example, Nov 20, the users will need to use this article to manually replace the library file?
Is it right? Thank you
The recommended solution would be to just upgrade to GA Server / Plus Nov 2021 Patch 1, but if that is not an option for them then they should apply the mitigations above until the relevant patch appears on the download site.
I saw may21 patch1 available in the download site. If we have add the flag for Qlik GeoAnalytics service properties. Do we still need to apply the may21 patch1?
Thanks
Hello @marthafong
We recommend an upgrade. The manual mitigation is just that, a mitigation, and the upgrade is intended to be the permanent fix.
Fyi, There is a SR3 of November 2021 of GeoAnalytics Server and Plus with log4J-2.17.1 as of Jan 26th.