Today, we have released eight service releases across the latest versions of Qlik Sense to patch the reported issue. All versions of Qlik Sense Enterprise for Windows prior to and including these releases are impacted:
February 2024 Patch 3
November 2023 Patch 8
August 2023 Patch 13
May 2023 Patch 15
February 2023 Patch 13
November 2022 Patch 13
August 2022 Patch 16
May 2022 Patch 17
No workarounds can be provided. Customers should upgrade Qlik Sense Enterprise for Windows to a version containing fixes for these issues. May 2024 IR, released on the 14th of May, contains the fix as well.
May 2024 Initial Release
February 2024 Patch 4
November 2023 Patch 9
August 2023 Patch 14
May 2023 Patch 16
February 2023 Patch 14
November 2022 Patch 14
August 2022 Patch 17
May 2022 Patch 18
This issue only impacts Qlik Sense Enterprise for Windows. Other Qlik products including Qlik Cloud and QlikView are NOT impacted.
Q: What steps can be used to reproduce the vulnerability? A: Qlik will not be providing steps on how to reproduce this test case.
Q: What authentication method is affected? A:Qlik strongly recommends moving to a patched version as per the bulletin, regardless of the authentication method used.
Q: Will Qlik Sense February 2022 or earlier be patched? A: See the Qlik Sense Enterprise on Windows Product Lifecycle (link) for information on what versions of Qlik Sense have reached End of Service (EOS). Versions which have reached EOS will not receive patches and Qlik strongly recommends moving to an up to date release.
The Security Notice label is used to notify customers about security patches and upgrades that require a customer’s action. Please subscribe to the ‘Security Notice’ label to be notified of future updates.
I second @jeremyseipel's comment. Seeing others bring up potential issues while upgrading and knowing how those issues can be avoided or fixed can help others to more successfully go through an upgrade process.
A good solution might be to create a post on the support blog, as suggested, and then make a comment here with a link to the blog post so that others would have visibility to issues and then follow the support blog post to offer and find solutions there.
In any case, thanks for putting together this support update! It's good to be aware of critical updates like this one.
We got repeatable questions regarding CVESecurity fixes from customers whose running offline environment. (i.e., not connected to the internet), is it still susceptible to these vulnerabilities ?
I strongly recommends applying the security patches or upgrading to a secure version of Qlik Sense Enterprise for Windows, i didn't find any feedback in any related articles for CVE, or any Qlik's declaration
We are planning to do upgrade in our platform. Will the vulnerabilities not fixed if we install Feb 2024 Latest patch (Patch 7) instead of Patch 4 or May 2024 latest patch (Patch3) instead of initial release.
This Vulnerability has been flagged by our Sec team as of June 2025. However our Qlik Sense Enterprise was already upgraded to Feb 2024 Patch 17, and the resolution already states that Feb 2024 patch 4 version has the fix to this vulnerability. Our systems are still lagged in the Registry key location in the server : : HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{xxxxxx-yyy-yyyy-yyyyyyyyy}
Can anyone guide the process to find any older Registry artifacts in the server pointing to the issue?.
As this vulnerability has been fixed, I recommend reaching out to Support with the information you've posted here, including all relevant details of your environment, as well as clarifying what you have discovered in your registry to help our support agents understand the issue.