peter bassill · operator
$ cve CVE-2023-48365 JSON

CVE-2023-48365 KEV

9.6
CRITICAL · CVSS 3.1 · EPSS 47.5% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2025-02-03.

Description

Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265.

Scoring

CVSS9.6 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS47.45% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-444
On CISA KEVyes — remediate by 2025-02-03
Public exploitnone known
Published2023-11-15
Last modified2026-06-17

CISA KEV

NameQlik Sense HTTP Tunneling Vulnerability
Added2025-01-13
Due2025-02-03
Vendor / productQlik / Sense
Ransomware useknown

Affected (1)

VendorProduct
qlikqlik sense

References

→ the Explorer  ·  watch your stack  ·  NVD