Today, we have released eight service releases across the latest versions of Qlik Sense to patch the reported issue. All versions of Qlik Sense Enterprise for Windows prior to and including these releases are impacted:
February 2024 Patch 3
November 2023 Patch 8
August 2023 Patch 13
May 2023 Patch 15
February 2023 Patch 13
November 2022 Patch 13
August 2022 Patch 16
May 2022 Patch 17
No workarounds can be provided. Customers should upgrade Qlik Sense Enterprise for Windows to a version containing fixes for these issues. May 2024 IR, released on the 14th of May, contains the fix as well.
May 2024 Initial Release
February 2024 Patch 4
November 2023 Patch 9
August 2023 Patch 14
May 2023 Patch 16
February 2023 Patch 14
November 2022 Patch 14
August 2022 Patch 17
May 2022 Patch 18
This issue only impacts Qlik Sense Enterprise for Windows. Other Qlik products including Qlik Cloud and QlikView are NOT impacted.
Q: What steps can be used to reproduce the vulnerability? A: Qlik will not be providing steps on how to reproduce this test case.
Q: What authentication method is affected? A:Qlik strongly recommends moving to a patched version as per the bulletin, regardless of the authentication method used.
Q: Will Qlik Sense February 2022 or earlier be patched? A: See the Qlik Sense Enterprise on Windows Product Lifecycle (link) for information on what versions of Qlik Sense have reached End of Service (EOS). Versions which have reached EOS will not receive patches and Qlik strongly recommends moving to an up to date release.
The Security Notice label is used to notify customers about security patches and upgrades that require a customer’s action. Please subscribe to the ‘Security Notice’ label to be notified of future updates.
Thank you for Sharing this, Would you be able to share steps which can be used to identify if the system is already compromised or not? This is very important to define whether the system was already infected before patching and other steps are needed or not. Can that be shared with partners confidentially at least ? Appreciate your help on this.
I tried the update but it crashed. Herewith the latest line from the log file :
5/05/2024 17:03:26 - Assessing service restore states 15/05/2024 17:03:26 - Assessing service restore state for QlikSenseServiceDispatcher 15/05/2024 17:03:26 - Restore state for Service is started: True 15/05/2024 17:03:26 - Assessing service restore state for QlikSenseRepositoryService 15/05/2024 17:03:26 - Restore state for Service is started: False 15/05/2024 17:03:26 - Assessing service restore state for QlikSenseEngineService 15/05/2024 17:03:26 - Restore state for Service is started: False 15/05/2024 17:03:26 - Assessing service restore state for QlikSenseProxyService 15/05/2024 17:03:26 - Restore state for Service is started: False 15/05/2024 17:03:26 - Assessing service restore state for QlikSensePrintingService 15/05/2024 17:03:26 - Restore state for Service is started: False 15/05/2024 17:03:26 - Assessing service restore state for QlikSenseSchedulerService 15/05/2024 17:03:26 - Restore state for Service is started: False 15/05/2024 17:03:26 - Assessing service restore state for QlikSenseRepositoryDatabase 15/05/2024 17:03:26 - Restore state for Service is started: False 15/05/2024 17:03:26 - Process id: 5896, Process name: QlikSenseServiceDispatcher 15/05/2024 17:03:26 - Process id: 0, Process name: QlikSenseRepositoryService 15/05/2024 17:03:26 - Process id: 0, Process name: QlikSenseEngineService 15/05/2024 17:03:26 - Process id: 0, Process name: QlikSenseProxyService 15/05/2024 17:03:26 - Process id: 0, Process name: QlikSensePrintingService 15/05/2024 17:03:26 - Process id: 0, Process name: QlikSenseSchedulerService 15/05/2024 17:03:26 - Stopping Service: QlikSenseServiceDispatcher. 15/05/2024 17:03:27 - QlikSenseServiceDispatcher was stopped 15/05/2024 17:03:27 - Dry run uninstall 15/05/2024 17:03:33 - Error! Validation of: C:\Program Files\Qlik\Sense\\Engine\Engine.exe failed: Le processus ne peut pas accéder au fichier 'C:\Program Files\Qlik\Sense\Engine\Engine.exe', car il est en cours d'utilisation par un autre processus. 15/05/2024 17:03:33 - Checking if file C:\Program Files\Qlik\Sense\\Engine\Engine.exe is locked... 15/05/2024 17:03:33 - Dry run uninstall done 15/05/2024 17:03:33 - Update failed 15/05/2024 17:03:33 - One or more of the files affected by the patch could not be changed. The following application(s) may be locking the files: Engine. 15/05/2024 17:03:33 - Exit code: -1
============================
When I try the update again I have the popup
"It is not possible to upgrade a rim node using Synchronized persistence. Please uninstall the existing version before installing this package."
Seems that I will have to uninstall/reinstall ... is there an other choice ?