Executive brief
Qlik Sense Enterprise for Windows contains an HTTP tunneling vulnerability due to improper validation of HTTP headers. An unauthenticated remote attacker can escalate privileges and execute HTTP requests on the backend repository application server, potentially leading to remote code execution. This issue is an incomplete fix for CVE-2023-41265.
Affected products
- Qlik Qlik Sense Enterprise for Windows Before August 2023 Patch 2; May 2023 before Patch 6; February 2023 before Patch 10; November 2022 before Patch 12; August 2022 before Patch 14; May 2022 before Patch 16; February 2022 before Patch 15; November 2021 before Patch 17
Timeline
- 2023-11-29: disclosed: Initial NVD analysis date
- 2025-01-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-01-13: advisory: Publication date of the advisory
- 2023-08-30: patched: Vendor released patches across multiple versions (August 2023 Patch 2 and others)
- 2025-01-13: exploited: Reported as exploited in the wild via CISA KEV catalog entry