Today, 20th of March 2024, we have released two service releases across the latest versions of QlikView to patch the reported issue. All versions of QlikView prior to and including the releases below are impacted:
QlikView May 2023 SR1 (12.80.20100)
QlikView May 2022 SR2 (12.70.20200)
Call to Action
As no workarounds can be provided, Customers should upgrade QlikView to one of the following versions that contain the fix:
QlikView May 2023 SR2 (12.80.20200)
QlikView May 2022 SR3 (12.70.20300)
This issue only impacts QlikView. Other Qlik data analytics products including Qlik Cloud and Qlik Sense Enterprise on Windows are not impacted.
Additional Details
All Qlik software can be downloaded from our official Qlik Download page (customer login required). Follow best practices when upgrading QlikView.
The Security Notice label is used to notify customers about security patches and upgrades that require a customer’s action. Please subscribe to the ‘Security Notice’ label to be notified of future updates.
Frequently Asked Questions
Q: Is the vulnerability present in the QlikView Plugin or other QlikView products? A: The vulnerability is related to the MSI files on disk.
Q: Will deleting the MSI files mitigate the issue? A: Qlik does not consider removing the MSI files a complete workaround. A server user can restore them.
I installed the IE plugin by extracting the MSI file from the QvPluginSetup.exe file.(Silent Installation) The version is May2023SR2. I understand that this issue has been resolved as May2023SR2 release. Does it matter which folder the MSI of fixed version May2023SR2 is located?
This is about Qlik Sense Enterprise for Windows Remote Code Execution (RCE) Vulnerability (Authenticated) - CVE-2023-48365, there is one asset detected with this vulnerability and per the below advisory there is no download page available in the download link, please advise
Customers shouldupgrade Qlik Sense Enterprise for Windows to a versioncontainingfixes for these issues.Fixes are availablefor thefollowingversions:
August 2023 Initial Release
May 2023 Patch 4
February 2023 Patch 8
November 2022 Patch 11
August 2022 Patch 13
All Qlik software can be downloaded from our official Qlik Download page (customer login required).
If you see problems accessing the download page, please contact our support agents through chat (the green Chat Now button in the bottom right corner of the screen). Provide them with information on what issue you are facing accessing the page (any error messages or a screenshot).
Thank you for your advise, I got below answer from the chat bot and found the link to download
To download Qlik Sense Enterprise, you can visit the Qlik Download Site. Here are the steps to download the installation files: Go to the Qlik Community website. Navigate to Support > Product News > Product Downloads. On the Product Downloads page, select "Qlik Data Analytics" or "Qlik Data Integration" based on your requirements. Choose the desired product from the available options. Use the filters to narrow down your list of possible downloads. Click on the download link in the Download Assets table to start the download. Please note that the specific version and release of Qlik Sense Enterprise may vary. Make sure to select the appropriate version that suits your needs.