CVE-2019-11628

Summary

CVECVE-2019-11628
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2019-05-01 03:29:00 UTC
Updated2020-08-24 17:37:00 UTC
DescriptionAn issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3, June 2018 Patch 3, September 2018 Patch 4, November 2018 Patch 4, or February 2019 Patch 2. An authenticated user may be able to bypass intended file-read restrictions via crafted Browser requests.

Risk And Classification

Problem Types: CWE-917

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Qlik Qlikview Server 11.20 service_release_1 All All
Application Qlik Qlikview Server 11.20 service_release_10 All All
Application Qlik Qlikview Server 11.20 service_release_11 All All
Application Qlik Qlikview Server 11.20 service_release_12 All All
Application Qlik Qlikview Server 11.20 service_release_13 All All
Application Qlik Qlikview Server 11.20 service_release_14 All All
Application Qlik Qlikview Server 11.20 service_release_15 All All
Application Qlik Qlikview Server 11.20 service_release_16 All All
Application Qlik Qlikview Server 11.20 service_release_17 All All
Application Qlik Qlikview Server 11.20 service_release_2 All All
Application Qlik Qlikview Server 11.20 service_release_3 All All
Application Qlik Qlikview Server 11.20 service_release_4 All All
Application Qlik Qlikview Server 11.20 service_release_5 All All
Application Qlik Qlikview Server 11.20 service_release_6 All All
Application Qlik Qlikview Server 11.20 service_release_7 All All
Application Qlik Qlikview Server 11.20 service_release_8 All All
Application Qlik Qlikview Server 11.20 service_release_9 All All
Application Qlik Qlikview Server 12.00 All All All
Application Qlik Qlikview Server 12.10 service_release_1 All All
Application Qlik Qlikview Server 12.10 service_release_2 All All
Application Qlik Qlikview Server 12.10 service_release_3 All All
Application Qlik Qlikview Server 12.10 service_release_4 All All
Application Qlik Qlikview Server 12.10 service_release_5 All All
Application Qlik Qlikview Server 12.10 service_release_6 All All
Application Qlik Qlikview Server 12.10 service_release_7 All All
Application Qlik Qlikview Server 12.10 service_release_8 All All
Application Qlik Qlikview Server 12.10 service_release_9 All All
Application Qlik Qlikview Server 12.20 service_release_1 All All
Application Qlik Qlikview Server 12.20 service_release_2 All All
Application Qlik Qlikview Server 12.20 service_release_3 All All
Application Qlik Qlikview Server 12.20 service_release_4 All All
Application Qlik Qlikview Server 12.30 service_release_1 All All
Application Qlik Qlikview Server 11.20 service_release_1 All All
Application Qlik Qlikview Server 11.20 service_release_10 All All
Application Qlik Qlikview Server 11.20 service_release_11 All All
Application Qlik Qlikview Server 11.20 service_release_12 All All
Application Qlik Qlikview Server 11.20 service_release_13 All All
Application Qlik Qlikview Server 11.20 service_release_14 All All
Application Qlik Qlikview Server 11.20 service_release_15 All All
Application Qlik Qlikview Server 11.20 service_release_16 All All
Application Qlik Qlikview Server 11.20 service_release_17 All All
Application Qlik Qlikview Server 11.20 service_release_2 All All
Application Qlik Qlikview Server 11.20 service_release_3 All All
Application Qlik Qlikview Server 11.20 service_release_4 All All
Application Qlik Qlikview Server 11.20 service_release_5 All All
Application Qlik Qlikview Server 11.20 service_release_6 All All
Application Qlik Qlikview Server 11.20 service_release_7 All All
Application Qlik Qlikview Server 11.20 service_release_8 All All
Application Qlik Qlikview Server 11.20 service_release_9 All All
Application Qlik Qlikview Server 12.00 All All All
Application Qlik Qlikview Server 12.10 service_release_1 All All
Application Qlik Qlikview Server 12.10 service_release_2 All All
Application Qlik Qlikview Server 12.10 service_release_3 All All
Application Qlik Qlikview Server 12.10 service_release_4 All All
Application Qlik Qlikview Server 12.10 service_release_5 All All
Application Qlik Qlikview Server 12.10 service_release_6 All All
Application Qlik Qlikview Server 12.10 service_release_7 All All
Application Qlik Qlikview Server 12.10 service_release_8 All All
Application Qlik Qlikview Server 12.10 service_release_9 All All
Application Qlik Qlikview Server 12.20 service_release_1 All All
Application Qlik Qlikview Server 12.20 service_release_2 All All
Application Qlik Qlikview Server 12.20 service_release_3 All All
Application Qlik Qlikview Server 12.20 service_release_4 All All
Application Qlik Qlikview Server 12.30 service_release_1 All All
Application Qlik Qlik Analytics april_2018 All All All
Application Qlik Qlik Analytics february_2018 All All All
Application Qlik Qlik Analytics february_2019 All All All
Application Qlik Qlik Analytics june_2017 All All All
Application Qlik Qlik Analytics june_2018 All All All
Application Qlik Qlik Analytics november_2017 All All All
Application Qlik Qlik Analytics november_2018 All All All
Application Qlik Qlik Analytics september_2017 All All All
Application Qlik Qlik Analytics september_2018 All All All
Application Qlik Qlik Analytics april_2018 All All All
Application Qlik Qlik Analytics february_2018 All All All
Application Qlik Qlik Analytics february_2019 All All All
Application Qlik Qlik Analytics june_2017 All All All
Application Qlik Qlik Analytics june_2018 All All All
Application Qlik Qlik Analytics november_2017 All All All
Application Qlik Qlik Analytics november_2018 All All All
Application Qlik Qlik Analytics september_2017 All All All
Application Qlik Qlik Analytics september_2018 All All All
Application Qlik Qlik Sense april_2018 All All All
Application Qlik Qlik Sense february_2018 All All All
Application Qlik Qlik Sense february_2019 All All All
Application Qlik Qlik Sense june_2017 All All All
Application Qlik Qlik Sense june_2018 All All All
Application Qlik Qlik Sense november_2017 All All All
Application Qlik Qlik Sense november_2018 All All All
Application Qlik Qlik Sense september_2017 All All All
Application Qlik Qlik Sense september_2018 All All All
Application Qlik Qlik Sense april_2018 All All All
Application Qlik Qlik Sense february_2018 All All All
Application Qlik Qlik Sense february_2019 All All All
Application Qlik Qlik Sense june_2017 All All All
Application Qlik Qlik Sense june_2018 All All All
Application Qlik Qlik Sense november_2017 All All All
Application Qlik Qlik Sense november_2018 All All All
Application Qlik Qlik Sense september_2017 All All All
Application Qlik Qlik Sense september_2018 All All All

References

ReferenceSourceLinkTags
SB: Improper Access Control Issue in QlikView Server and Qlik Sense Enterprise MISC qliksupport.force.com Vendor Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report