3 min read
E-mergo support: no worries about vulnerabilities

In today's fast-changing digital world, no one can escape it: vulnerabilities in the software you use. All software companies are constantly innovating, and a mistake is easily made. Once a leak is found and published, a race against the clock begins, because as soon as you know about it, criminal hackers know about it too, so you need to make sure the leak gets patched. Last September there was such a leak, classified as "Critical," affecting all client-managed versions of Qlik. In this blog, Senior Consultant Lennaert van den Brink tells you more about how our support department handled it.
That publication usually happens via the vulnerability database of the American National Institute of Standards and Technology (NIST). The leak is entered into this database and given a so-called CVE (Common Vulnerabilities and Exposures) number. Using that number, you can look up the severity of the leak, how likely it is to be actively exploited, and which software is affected by it.
Qlik CVE notice
Last September there was such a CVE, classified as "Critical," affecting all client-managed versions of Qlik: CVE-2023-41265. The E-mergo support team took action immediately: all clients with a support contract were informed of the leak. An upgrade of the systems was then scheduled with them.
Normally that would be the end of it, but in this case the operation had a follow-up. The patch meant to fix the problem turned out not to fully close the leak after all, which led to a new CVE: CVE-2023-48365. Because E-mergo's support team closely monitors vulnerabilities, they were able to act quickly and these clients were still provided with the correct fix.
For readers of this blog who don't (yet) have support from E-mergo: if you're on one of the versions below, make sure you upgrade as soon as possible to at least the most recent patch for that version. The affected versions are:
- August 2023 Patch 1
- May 2023 Patch 5
- February 2023 Patch 9
- November 2022 Patch 11
- August 2022 Patch 13
- May 2022 Patch 15
- February 2022 Patch 14
- November 2021 Patch 16

Written by Lennaert van den Brink
Senior Consultant