Sense vulnerabilities
3 published alerts for Qlik Sense.
Qlik Sense HTTP Tunneling Vulnerability
Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-48365). Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. CISA remediation due date: 2025-02-03. If you need help checking exposure, call (864) 335-9223.
Qlik Sense Path Traversal Vulnerability
Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-41266). Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. CISA remediation due date: 2023-12-28. If you need help checking exposure, call (864) 335-9223.
Qlik Sense HTTP Tunneling Vulnerability
Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-41265). Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. CISA remediation due date: 2023-12-28. If you need help checking exposure, call (864) 335-9223.