Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content
Announcements
March 26 at 10am ET: See how Qlik drives growth and value in ISV segment - REGISTER NOW
Sonja_Bauernfeind
Digital Support
Digital Support

Edited December 5th: identified upgrades leading to complications with extensions
Edited December 6th: added workaround for extension complication
Edited December 10th: added CVEs (CVE-2024-55579 and CVE-2024-55580)
Edited December 12th, noon CET: added new patch versions and visualization and extension fix details; previous patches were removed from the download site

Hello Qlik Users,

New patches have been made available and have replaced the original six releases. They include the original security fixes (CVE-2024-55579 and CVE-2024-55580) as well as QB-30633 to resolve the extension and visualization defect.

If you continue to experience issues with extensions or visualizations, see QB-30633: Visualizations and Extensions not loading after applying patch.

Security issues in Qlik Sense Enterprise for Windows have been identified, and patches have been made available. Details can be found in Security Bulletin High Severity Security fixes for Qlik Sense Enterprise for Windows (CVE-2024-55579 and CVE-2024-5558....

Today, we have released six service releases across the latest versions of Qlik Sense to patch the reported issue. All versions of Qlik Sense Enterprise for Windows prior to and including these releases are impacted:

  • May 2024 Patch 9
  • February 2024 Patch 13
  • November 2023 Patch 15
  • August 2023 Patch 15
  • May 2023 Patch 17
  • February 2023 Patch 14

 

No workarounds can be provided. Customers should upgrade Qlik Sense Enterprise for Windows to a version containing fixes for these issues. November 2024 IR, released on the 26th of November, contains the fix as well

  • November 2024 Initial Release
  • May 2024 Patch 10 or 11 (both valid)
  • February 2024 Patch 14 or 15 (both valid)
  • November 2023 Patch 16 or 17 (both valid)
  • August 2023 Patch 16 or 17 (both valid)
  • May 2023 Patch 18 or 19 (both valid)
  • February 2023 Patch 15 or 16 (both valid)
This issue only impacts Qlik Sense Enterprise for Windows. Other Qlik products including Qlik Cloud and QlikView are NOT impacted.

All Qlik software can be downloaded from our official Qlik Download page (customer login required). Follow best practices when upgrading Qlik Sense.

The information in this post and Security Bulletin High Severity Security fixes for Qlik Sense Enterprise for Windows (CVE-2024-55579 and CVE-2024-5558... are disclosed in accordance with our published Security and Vulnerability Policy.

 

The Security Notice label is used to notify customers about security patches and upgrades that require a customer’s action. Please subscribe to the ‘Security Notice’ label to be notified of future updates. 

Thank you for choosing Qlik,
Qlik Global Support

129 Comments
williamandersson
Partner - Contributor III
Partner - Contributor III

@henrikalmen Hi!
Have you experienced any issues going from May24 P10 to P11? We are about to move to this patch as well, with testing in dev first.

1,453 Views
henrikalmen
Specialist II
Specialist II

@williamandersson I haven't experienced any differences after applying P11 from P10. I don't even know what was possibly fixed in the P11 release. So no, I haven't seen any new issues with P11.

1,424 Views
prinzchristian
Partner - Contributor III
Partner - Contributor III

QSoW Patch November 2024 SP1 --> Problem with SAP Connector!!!

Has anyone already changed the behavior with the SAP Connectors with the 2024 November patch 2 tested?

Github - Release November 2024 Patch 2 

 

UPDATE - 2024.05 Patch 11: 

I now get the same behavior with the patch to the latest May release - how am I supposed to close the gaps if I get a non-working system in return?

prinzchristian_0-1734001196747.png

After uninstalling the patch, the connector will run as usual on the original May 2024 version.

 

UPDATE - 2024.05 Patch 11 | 2025.01

I can confirm the following solution and it works with patch 11 - update to 2024 Nov. Patch 2 is then planned for next week.

Edited by Qlik: removed solution, This configuration change reverts recent security improvements made to the product and could lead to users being able to execute unintended code on the server.

 

Qlik Case Number: 
# 00334265: SAP Connector in Qlik Sense using Standard mode is not working anymore

1,374 Views
makunii
Partner - Contributor III
Partner - Contributor III

Hello @Benoit_C @M_B

Could you tell me what is the Qlik Sense version? And what is the issue you are facing?

Thank you.

Regards.

Marco

0 Likes
1,275 Views
M_B
Creator
Creator

@makunii

Qlik Sense May 2024 Patch 11 - 14.187.17

The issue seemed to have started after installing patch 10 for us. There were no complaints before that. When opening the mobile app or browser through our external link (we usually access Qlik through the internet), the hub loads just fine and displays all streams and apps. When we try to open an app, we encounter a blank page (whether through the mobile app (Client-Managed - Qlik Sense Mobile February 2024 1.25.2.1) or browser (any browser)). Refreshing the page a couple dozen time might get you to the app but that is extremely unreliable and impractical.

The setup is 2 consumer nodes behind a URL and physical load balancer. I do not face this issue when using the FQDN of the server/machine name.

User eyalnir_qlik seems to be having a similar issue and has opened a support ticket.

Please read through my earlier posts for other information.

1,224 Views
M_B
Creator
Creator

@Benoit_C , @makunii 

Reverting to May 2024 Patch 6 resolved the issue. Opening apps through mobile app and browsers is working again.

Hopefully an update containing fixes for both the new CVEs and issue QB-30710 is released soon.

Thanks in advance.

1,171 Views
steeefan
Luminary
Luminary

Yesterday and today I woke up to alarm messages by our monitoring software, alerting me to the fact that the C: drive of our QS Prod server is about to be clogged up

I believe that ever since installing February 2024 Patch 14, the size of the file C:\ProgramData\Qlik\Sense\Log\governanceLogContent_7.18.0_file.qvd is spiraling out of control. It currently clocks in at 40.9gb. That has never happened before.

Is anyone else seeing something similar?

0 Likes
1,073 Views
TomBond77
Specialist
Specialist

Thanks for this information. 

We are running August 2022, therefore no need for this security patch, correct?

0 Likes
835 Views
p_verkooijen
Partner - Specialist II
Partner - Specialist II

@TomBond77 

As stated

  • All versions of Qlik Sense Enterprise for Windows prior to and including these releases are impacted.
  • No workarounds can be provided. Customers should upgrade Qlik Sense Enterprise for Windows to a version containing fixes for these issues.

Version August 2022 is EOS (End Of Support) since August 23, 2024, no patches will be made available for this release.

So you have to upgrade your environment (and patch based on the version you are upgrading to)

 

0 Likes
815 Views
jeremyseipel
Partner - Contributor III
Partner - Contributor III

@Sonja_Bauernfeind is there going to be an additional patch released by Qlik that resolves the original CVE issues, includes the updates required for visualization issues, and the additional issues being reported by users since the latest patch was released?  Based on the last few pages of responses I am hesitant to upgrade environments since there are still a variety of issues reported, but at the same time know the vulnerability needs to be closed.  

696 Views