Qlik Sense security update advisories

Overview

 

An update has been released to address vulnerabilities in Qlik Sense. Users of the affected versions are advised to update to the latest version.
 

 

Affected Products

 

CVE-2024-55579, CVE-2024-55580

 

Qlik Sense Enterprise for Windows

  • May 2024 Patch 9
  • February 2024 Patch 13
  • November 2023 Patch 15
  • August 2023 Patch 15
  • May 2023 Patch 17
  • February 2023 Patch 14

 

 

Resolved Vulnerabilities

 

Vulnerability in Qlik Sense Enterprise for Windows that allows unauthorized users with network access to create a crafted object that could allow them to execute arbitrary EXE files (CVE-2024-55579)

Vulnerability in Qlik Sense Enterprise for Windows that could allow an unauthorized user with network access to execute remote commands, posing a serious threat to the availability, integrity, and confidentiality of the system (CVE-2024-55580)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-55579, CVE-2024-55580

 

Qlik Sense Enterprise for Windows

  • November 2024 Initial Release
  • May 2024 Patch 10
  • February 2024 Patch 14
  • November 2023 Patch 16
  • August 2023 Patch 16
  • May 2023 Patch 18
  • February 2023 Patch 15

 

 

 

Referenced Sites

 

[1] CVE-2024-55579 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-55579

[2] CVE-2024-55580 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-55580

[3] High Security fixes for Qlik Sense Enterprise for Windows (CVE-2024-55579 and CVE-2024-55580)

https://community.qlik.com/t5/Official-Support-Articles/High-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows-CVE/tac-p/2496004