QID 730994
Date Published: 2023-12-19
QID 730994: Qlik Sense Enterprise for Windows Multiple Security Vulnerabilities
Qlik Sense is a self-service data visualization and discovery application designed for individuals and group collaboration.
Qlik Sense Enterprise for Windows prior to and including these releases contain the following vulnerabilities:
CVE-2023-48365 (QB-21683) HTTP Tunneling vulnerability in Qlik Sense Enterprise for Windows.
CVE-2023-41266 (QB-21220) Path traversal in Qlik Sense Enterprise for Windows.
CVE-2023-41265 (QB-21222) HTTP Tunneling vulnerability in Qlik Sense Enterprise for Windows
Affected Versions:
August 2023 Patch 1
May 2023 Patch 5
February 2023 Patch 9
November 2022 Patch 11
August 2022 Patch 13
May 2022 Patch 15
February 2022 Patch 14
November 2021 Patch 16
QID Detection Logic:
This QID detects vulnerable versions of the application based on directory traversal requests to /resources/qmc/fonts/../../../qrs/ReloadTask resource.
Depending on the vulnerability being exploited, an unauthenticated, remote attacker could exploit these vulnerabilities to conduct path traverversal or execute arbitrary code on a targeted system.
CVEs related to QID 730994
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2120510 |
|