Junglewise Threat Intelligence

CVE-2023-41265: Qlik Sense HTTP Tunneling Vulnerability

CVE-2023-41265 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2023-12-07

Technologies: Qlik Sense. Vendors: Qlik.

Executive brief

Qlik Sense Enterprise for Windows contains an HTTP Request Tunneling vulnerability due to inconsistent interpretation of HTTP requests. A remote attacker can elevate privileges by tunneling requests in a raw HTTP request, allowing them to execute unauthorized commands on the backend repository application server.

Affected products

  • Qlik Qlik Sense Enterprise for Windows May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, August 2022 Patch 12 and earlier

Timeline

  • 2023-09-08: disclosed: Initial NVD analysis date
  • 2023-12-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats