CVE-2023-48365

CRITICAL(9.6)KEVRansomwareElevated Risk

Qlik Sense HTTP Tunneling Vulnerability

Description

Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265.

KEV Information

Vendor
Qlik
Product
Sense
Date Added
January 13, 2025
Due Date
February 3, 2025
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
5.8

CWEs

Affected Products

VendorProductVersion
qlikqlik senseaugust_2022; august_2023; february_2022; february_2023; may_2022; may_2023; november_2021; november_2022

Multiple CVSS Assessments

Source: [email protected](Secondary)
9.6
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Source: [email protected](Primary)
9.9
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References

CVSS Score

9.6
CRITICAL(9.6)

EPSS Score

EPSS Score24.68%
EPSS Percentile97.7%

Dates

PublishedNovember 15, 2023
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.