Qlik is aware that a set of well publicized vulnerabilities have been identified in the popular Java Spring Framework. These vulnerabilities have been assigned references CVE-2022-22965 (also known as "Spring4Shell"), CVE-2022-22947, CVE-2022-22950 and CVE-2022-22963.
CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ (Critical)CVE-2022-22947: Spring Cloud Gateway Code Injection Vulnerability (Critical)
CVE-2022-22963: Remote code execution in Spring Cloud Function by malicious Spring Expression (Critical)
CVE-2022-22950: Spring Expression DoS Vulnerability (Medium)
Qlik has been diligently reviewing our product suite since we’ve become aware of these issues. We want to ensure Qlik users that your security is our upmost priority. As always, we recommend customers stay up-to-date on the most recent releases available for your product.
Products Not Impacted
The following products are NOT affected:
Qlik Cloud
Client-Managed Qlik Sense Enterprise and QlikView (all versions)
GeoAnalytics (all versions)
Qlik Compose (all versions)
Qlik Compose for Data Lakes (all versions)
Qlik Compose for Data Warehouses (all versions)
Qlik Enterprise Manager (all versions)
Qlik NPrinting
Qlik Replicate (all versions) **
** Qlik Replicate contains libraries that contain the affected code, but they are not used in a way that is exploitable. These will be removed in a upcoming patch.
Products Impacted
Our testing shows only client-managed versions of Qlik Catalog are directly impacted (by CVE-2022-22965 and CVE-2022-22950) and a patch will be available as Feb 2022 SR2 and for the May 2022 release. Mitigation steps for earlier releases are linked in this knowledge base article.
Update 4/04/2022 8:15p.m EST
Qlik Catalog Feb 2022 SR2 is now available on the Downloads Site.Please be sure to be logged into Qlik Community with your Qlik ID to access.
Please subscribe to our Support Updates blog for continued updates as they become available.
Thank you for choosing Qlik,
Qlik Global Support
...View More
“How can Imonitorreloads across the tenant?”
“HowcanI see what data connections and files are being used?”
“How can I view reload concurrencyand peak reload RAM over time?”
Tohelp answer these questions,we arehappy to share with you the capabilities of our ReloadAnalyzer for Qlik Sense SaaS!
TheReloadAnalyzer app provides insights on:
Number of reloads by type (Scheduled, Hub, In App, API) and by user
Data connectionsand used filesof each app’s most recent reload
Reload concurrency and peak reload RAM
Reload tasksand their respective statuses
And much more!
(Availablesheets)
TheReloadAnalyzer usesQlik’s RESTful APIsto fetch all the required data andstoresthe history in QVD files, allowing for efficient reloads andhistorical analysis.
A few things to note:
This app is provided as-is and is not supported by Qlik Support.
It is recommended to always use the latest app.
Information is not collected by Qlik when using this app.
The app as well as the configuration guide are available via GitHub, linked below.
QVF: https://github.com/qlik-oss/qlik-cloud-reload-analyzer/releases/latest/download/reload-analyzer.qvf
Release Notes:https://github.com/qlik-oss/qlik-cloud-reload-analyzer/releases/latest
Installation Guide: https://github.com/qlik-oss/qlik-cloud-monitoring-apps/releases/latest/download/qlik-cloud-monitoring-applications-installation-guide.pdf
Anyissues or enhancement requestsshould be opened on theIssues pagewithin the app’s GitHub repository.
Be sure to subscribe to the Qlik Support Updates Blog by clicking the green Subscribe button to stay up-to-date with the latest Qlik Support announcements. Please give this post a like if you found it helpful!
Kind regards,
Qlik Digital Support Team
Additional Resources:
Our other monitoring apps for Qlik Cloud can be found below.
App Analyzer
Entitlement Analyzer
Access Evaluator
OEM Dashboard(for OEM Partners and multi-cloud tenants)
...View More
We arehappy to share with you the new EntitlementAnalyzer for Qlik Sense Enterprise SaaS!This application will enable you to answer questions like:
How can I track the usage of my Tenant over time? How are myentitled users using the Tenant?
Howcan IbetterunderstandtheusageofAnalyzer Capacityvs.Analyzer & Professional Entitlements?
The Entitlement Analyzer is only available for Qlik Cloud subscription types. Refer to the compatibility matrix within the Qlik Cloud Monitoring Apps repository for an overview of which monitoring app is compatible with which subscription type.
The EntitlementAnalyzer app provides insights on:
Entitlementusageoverview across the Tenant
Analyzer Capacity – Detailed usage dataand a predication if you have enough
How users are using the system and if they have the rightEntitlement assigned to them
Which Apps are used the most by using the NEW "App consumption overview" sheet
And much more!
The Entitlement Analyzer uses a new API Endpoint to fetch all the required data and will storethe history in QVD files to enable even better Analytics over time.
A few things to note:
This app is provided as-is and is not supported by Qlik Support.
It is recommended to always use the latest app.
Information is not collected by Qlik when using this app.
The app as well as the configuration guide are available via GitHub, linked below.
QVF:https://github.com/qlik-oss/qlik-cloud-entitlement-analyzer/releases/latest/download/entitlement-analyzer.qvf
Release Notes:https://github.com/qlik-oss/qlik-cloud-entitlement-analyzer/releases/latest
Installation Guide:https://github.com/qlik-oss/qlik-cloud-monitoring-apps/releases/latest/download/qlik-cloud-monitorin...
Anyissues, questions, and enhancement requestsshould be opened on theIssues pagewithin the app’s GitHub repository.
Be sure to subscribe to the Qlik Support Updates Blog by clicking the green Subscribe button to stay up to date with the latest Qlik Support announcements. Please give this post a like if you found it helpful!
Kind regards,
Qlik Platform Architects
Additional Resources:
Our other monitoring apps for Qlik Cloud can be found below.
App Analyzer
Reload Analyzer
Access Evaluator
OEM Dashboard (for OEM Partners and multi-cloud tenants)
...View More
Hello Qlik Users,Today we have seven Qlik Sense patches and one for Qlik Connector for use with SAP NetWeaver:February 2021 Patch 5November 2020 Patch 10September 2020 Patch 12June 2020 Patch 16April 2020 Patch 16February 2020 Patch 12November 2019 Patch 17SAP NetWeaver 7.0.7These patches include a fix for the security vulnerability, details of which can be found in the Security Bulletin SB: Cross-site scripting (XSS) vulnerability in Qlik Sense Enterprise.The downloads for the patches can all be found on the Qlik Download site. The release notes for SAP NetWeaver can also be found on the Qlik Download site.Release Notes for the Qlik Sense patches can be found in the Qlik Community, on the new Release Notes page.Please follow best practices when upgrading Qlik Sense.The information in this post and Security Bulletin are disclosed in accordance with our published Security and VulnerabilityPolicy.Kind regards,Qlik Global Support5/25/2021 - Update to clarify a couple of questions:The versions listed in the Security Bulletin are the fixed versions. Versions prior to those listed are the affected versions.If you do not use the SAP connector, you still need to apply the patch for Qlik Sense.There is a new release that includes the security fix as well so you will most likely want to apply that patch (both do not need to be applied in that case).
...View More
Hello Qlik Users,Looking for some tips on Qlik Replicate task configuration with Microsoft SQL Server as the source? Look no further! A member of the Qlik Replicate support team came up with these tips for you. Check them out!5 Tips for Qlik Replicate task configuration with MS SQL Server as sourceIs there anything else you would like to see some tips on? Let us know in the comments below!Thank you for choosing Qlik!Kind regards,Qlik Digital Support
...View More
Hello Qlik Users!I’m always amazed at what our users create using Qlik products. Today’s Featured Content Friday is no exception. He’s a long-time user (about 20 years) and holds the Owner, CEO, and Consultant titles for his own company.Robert of Svebeck Consulting AB!Robert says his favorite thing about Qlik is:The app Robert created is so unique. It shares a visual story.I’ll let Robert tell you in his own words about his creation:“The story behind this chart started with me talking to Shirajul Kabir Rab who I collaborate with a lot on Data On The Rocks and Data On The Earth.We were talking about trying to find new ways to visualize data, when the idea of visualizing data in a simple landscape came to us.Since I have been investigating a lot on the Map Object I realised that it is possible to make a Mock-Up chart using the map object to try the idea out.In parallel to this I also had an idea to make a chart that would be a new kind of network chart, or like a combination of the Scatter chart and a Sankey chart, basically trying to find a way to visualize how one “dot” in the scatter is connected to another “dot” in the scatter. The more ways a dot is connected to another dot, the more lines connects them. I realised that it was possible to make this chart, again as a Mock-Up, using the map chart.Since the result of this new kind of chart made the object look like birds, I decided to combine this new chart (that I named Seagull Chart) with the idea of a Landscape chart, and this is the result.In this example, the code is not really re-usable in a simple way for a business application – and should be seen rather as inspiration for new ways of displaying data.I decided to see the birds as existing customers where the 3 dots that shape the bird represents 3 months of sales. The number of lines between the dots represents how diverse the customer is buying in a scale from 1-3, meaning 3 lines = they buy all kinds of material and 1=they buy as limited amount of material.The idea of the birds flying in the sky, just like in a scatter chart their position (where they fly) are also carrying a purpose, the closer to the sun, or the higher up, the better “Customers”.To add more features to the landscape I added a flower object in the bottom which would represent prospects.The Landscape concept can be applied also to other kind of data (not just Sales), such as this: flowers are new projects, birds are “employees”, and active projects are perhaps trees in the landscape, and employees who are working on a project are “circulating” around that tree. It can become anything, the concept is really interesting. Was also thinking about other kinds of landscapes, with rivers and mountains. It can visualise many cool things.The script is very simple, and I am just generating random data to fit the different layers in the map-object.Not sure how much is needed to explain the map object, as this is pretty self explained for those who know how the map object works.And the point of this app is not to explain How this is done, rather inspire chart developers to do something new.”You can find Robert’s original post on LinkedIn:Landscape Chart**The information in this post is provided as-is and to be used at your own discretion. Depending on the tool(s) used, customization(s), and/or other factors ongoing support may not be provided by Qlik Support.Robert also supplied the app and images. You can find the attachments below. Take a look and play around. Hopefully, it will inspire you as well!Thank you@RSvebeckfor sharing your landscape chart with us!Do you want to be spotlighted in a future post? See our Featured Content Friday Revamp for more information on submitting your dashboards, screenshots, ideas, videos, workarounds, how-to’s, and for your chance to win some Qlik swag!Thank you for being a part of the Qlik Community and choosing Qlik!Kind regards,Qlik Digital Support
...View More
Hello Qlik Users!
If you are on the Qlik Sense App Development forum or the QlikView App Dev forum, you might see some very seasoned developers writing line after line of code. You might be asking yourself, “what does all this mean!?” It can look intimidating.
One of the possibilities, is that the code is for Set Analysis.
Set analysis gives you a way to define a set or a group of values that is independent of any selections. It is commonly used for making comparisons (e.g. this year vs last year). With set analysis, you use set expressions to analyze data.
Set expressions are how you define the field values. A set expression must be used in an aggregation function (like sum) and it must be enclosed by braces, {}. The expression consists of operators, identifiers and modifiers.
Here are some suggestions on how to get started with Set Analysis and Set Expressions:
Keep it simple.
Play around with examples provided on Qlik Help*. Get familiar with the syntax and the structure of the expressions.
Take a self-paced class on our Learning portal.
We offer a few classes on set expressions and set analysis:
Introduction to Set Expressions
Advanced Set Expressions
Leveraging Set Analysis
Review our video resources.
There are so many videos available on Set Analysis. Some of the videos are a little bit older, but they are still relevant. Here are a couple I recommend:
Do More with Qlik Webinar Series – Set Analysis
Qlik Sense in 60 – Set Analysis
Search the Qlik Community.
There is so much content that has been created in the form of articles, Help documentation, Community posts and documents, YouTube videos, etc. One search will search all the available platforms so you do not have to scour the internet.
Ask your peers for help.
Use our Qlik Community forums (Qlik Sense App Development and QlikView App Dev) to get help from your peers. I love promoting our Community’s development resources. The developers out on Qlik Community are brilliant and eager to help.
Try out the Set Analysis Wizard for QlikView**
The Set Analysis Wizard for QlikView is not a Qlik tool but was created by an employee. It is also something we like to use in Qlik Support. Even though it says for QlikView, it still applies to Qlik Sense.
I hope these resources help you on your Set Analysis journey. If you have any suggestions or recommendations on materials that helped you learn Set Analysis, post them in the comments below.
Kind regards,
Qlik Digital Support
*The same document is also available for QlikView.
**The information in this post is provided as-is and to be used at own discretion. Depending on tool(s) used, customization(s), and/or other factors ongoing support may not be provided by Qlik Support.
...View More
Hello Qlik Users!Today’s Featured Content Friday has been using Qlik for 13 years as a Qlik Partner, a Luminary, a MVP, and now an employee! He is a Senior Solution Architect and has been with Qlik for three years now. He is located in Brazil.Clever of Qlik!Clever says his favorite thing about Qlik is:Qlik-cli is a PowerShell module that allows the Qlik Sense environment to be managed through command line. Clever shared an example of using the command line to evaluate a KPI so you can take immediate action. You can view his post out on the Qlik Community (the post is in Portuguese so you may need to translate the page):Performing calculations on your Qlik Sense in SaaS using command line**The information in this post is provided as-is and to be used at own discretion. Depending on tool(s) used, customization(s), and/or other factors ongoing support may not be provided by Qlik Support.If you’re unfamiliar with qlik-cli, here are some additional resources for you:Get started with qlik-cliqlik-cli on Qlik DeveloperWould you like to be spotlighted in a future post? See our Featured Content Friday Revamp for more information on submitting your dashboards, screenshots, ideas, videos, workarounds, how-to’s and for your chance to win some Qlik swag!Thank you for being a part of the Qlik Community and for choosing Qlik!Kind regards,Qlik Digital Support
...View More