Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
Update 21st of March 16:00 CET: published CVE number
Update 27th of March 10:45 CET: added FAQ
Hello Qlik Users,
A security issue in QlikView has been identified and patches have been made available. Details can be found in the Security Bulletin High Severity Security fix for QlikView (CVE-2024-29863).
Today, 20th of March 2024, we have released two service releases across the latest versions of QlikView to patch the reported issue. All versions of QlikView prior to and including the releases below are impacted:
As no workarounds can be provided, Customers should upgrade QlikView to one of the following versions that contain the fix:
This issue only impacts QlikView. Other Qlik data analytics products including Qlik Cloud and Qlik Sense Enterprise on Windows are not impacted.
The Security Notice label is used to notify customers about security patches and upgrades that require a customer’s action. Please subscribe to the ‘Security Notice’ label to be notified of future updates.
Q: Is the vulnerability present in the QlikView Plugin or other QlikView products?
A: The vulnerability is related to the MSI files on disk.
Q: Will deleting the MSI files mitigate the issue?
A: Qlik does not consider removing the MSI files a complete workaround. A server user can restore them.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.