Skip to main content
Announcements
Join us at Qlik Connect for 3 magical days of learning, networking,and inspiration! REGISTER TODAY and save!
cancel
Showing results for 
Search instead for 
Did you mean: 
mj26
Partner - Contributor III
Partner - Contributor III

VAPT Qualys scan on our Qlik reporting server error/findings

Hi Qlik Fam,

Requesting assistance for the error encountered upon conducting a VAPT Qualys scan on our Qlik reporting server, which has shown 3 vulnerable, we would appreciate your insights on the following vulnerable listed below:

1. HTTP Security Header Not Detected
2. Secure Sockets Layer/Transport Layer Security (SSL/TLS) server supports Transport Layer Security (TLSv1.0)
3. TLS Padding Oracle Vulnerability (Zombie POODLE and GOLDENDOODLE)

Thank you in  advance. 

Labels (5)
1 Reply
mpc
Partner - Specialist II
Partner - Specialist II

Hi, 

Please execute IIS Crypto to disable weak cipher suite/TLS protocol: https://www.nartac.com/Products/IISCrypto

Then perform a new scan of your server. 

Kind regards

From Next Decision and mpc with love
It helps, like it, It solves, mark it