Executive brief
A path traversal vulnerability in Qlik Sense Enterprise for Windows allows unauthenticated remote attackers to generate anonymous sessions via crafted HTTP requests. These sessions can be used to bypass authorization and access unauthorized endpoints.
Affected products
- Qlik Qlik Sense Enterprise for Windows May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, August 2022 Patch 12 and earlier
Timeline
- 2023-08-29: disclosed: NVD Published Date
- 2023-12-07: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2023-12-07: exploited: Reported as exploited in the wild in advisory metadata