Skip to main content
Announcements
Qlik Connect 2024! Seize endless possibilities! LEARN MORE
cancel
Showing results for 
Search instead for 
Did you mean: 
Vikki
Contributor II
Contributor II

Qlik Visibility - Spring Framework vulnerability CVE-2022-22965

Looking for guidance on Attunity Visibility software v7.3 impact for Spring Framework vulnerability CVE-2022-22965. PNC Security has requested remediation as per below:

Spring Framework contains a flaw in the CachedIntrospectionResults class in spring-beans/src/main/java/org/springframework/beans/CachedIntrospectionResults.java related to insecure introspection when using request parameter binding. This may allow a remote attacker to invoke arbitrary Java class methods and execute arbitrary code. 


I've found the reference in your support documentation for the subject CVE vulnerability but there is no mention of Qlik Visibility software. Would appreciate some help.

Using:

Operating System: Linux
Operating System Version: RHEL 7.9
Product Release: V7.3
Environment Type: Production


Thank you,
Vikki Turner

Labels (1)
2 Solutions

Accepted Solutions
lyka
Support
Support

Good Day!

 

Visibility is a retired product and no longer supported

 

https://community.qlik.com/t5/Support-Updates-Blog/Retirement-of-legacy-Attunity-products-on-January...

 

Thanks

Lyka

View solution in original post

Nanda_Ravindra
Support
Support

 @Vikki I checked with the R&D team, and they did confirm that it needs a code rebuild and since the product has reached the end of life, we won't be able to build the code and share the new build.

 

https://community.qlik.com/t5/Support-Updates-Blog/Retirement-of-legacy-Attunity-products-on-January...

 

Thanks,

Nanda

View solution in original post

3 Replies
lyka
Support
Support

Good Day!

 

Visibility is a retired product and no longer supported

 

https://community.qlik.com/t5/Support-Updates-Blog/Retirement-of-legacy-Attunity-products-on-January...

 

Thanks

Lyka

Nanda_Ravindra
Support
Support

Hello @Vikki 

              The spring Framework vulnerability  listed here is  more involved and would probably require code changes. Since the product has reached end of life,  I am not sure if  R&D can rebuild installation kit for you with the fix.  That being said, I am checking with development team on this to see if we can help you in anyway. So, give me some time and I'll get back to you on this.

 

Thanks,

Nanda

Nanda_Ravindra
Support
Support

 @Vikki I checked with the R&D team, and they did confirm that it needs a code rebuild and since the product has reached the end of life, we won't be able to build the code and share the new build.

 

https://community.qlik.com/t5/Support-Updates-Blog/Retirement-of-legacy-Attunity-products-on-January...

 

Thanks,

Nanda