Executive brief
Qlik Sense Enterprise for Windows contains an HTTP Request Tunneling vulnerability due to inconsistent interpretation of HTTP requests. A remote attacker can elevate privileges by tunneling requests in a raw HTTP request, allowing them to execute unauthorized commands on the backend repository application server.
Affected products
- Qlik Qlik Sense Enterprise for Windows May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, August 2022 Patch 12 and earlier
Timeline
- 2023-09-08: disclosed: Initial NVD analysis date
- 2023-12-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog