Qlik Sense HTTP Tunneling Vulnerability
Critical CVSS 9.6 Listed in CISA KEV
Summary
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Qlik:Sense
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2023-41265 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801; reference
- https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801 Vendor Advisory
- https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes Release Notes
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41265 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD