← Back

CVE-2019-11628

nvd nist
Published: May 1, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3, June 2018 Patch 3, September 2018 Patch 4, November 2018 Patch 4, or February 2019 Patch 2. An authenticated user may be able to bypass intended file-read restrictions via crafted Browser requests.

Affected (50)

3 products
Qlikview Server
Qlik Analytics
Qlik Sense
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Qlik
Version 11.20 service_release_10
Version 11.20 service_release_11
Version 11.20 service_release_12
Version 11.20 service_release_13
Version 11.20 service_release_14
Version 11.20 service_release_15
Version 11.20 service_release_16
Version 11.20 service_release_17
Version 11.20 service_release_1
Version 11.20 service_release_2
Version 11.20 service_release_3
Version 11.20 service_release_4
Version 11.20 service_release_5
Version 11.20 service_release_6
Version 11.20 service_release_7
Version 11.20 service_release_8
Version 11.20 service_release_9
Version 12.00
Version 12.10 service_release_1
Version 12.10 service_release_2
Version 12.10 service_release_3
Version 12.10 service_release_4
Version 12.10 service_release_5
Version 12.10 service_release_6
Version 12.10 service_release_7
Version 12.10 service_release_8
Version 12.10 service_release_9
Version 12.20 service_release_1
Version 12.20 service_release_2
Version 12.20 service_release_3
Version 12.20 service_release_4
Version 12.30 service_release_1
Configuration B
18 vulnerable
Vulnerable SoftwareAffected Versions
Qlik
Version april_2018
Version february_2018
Version february_2019
Version june_2017
Version june_2018
Version november_2017
Version november_2018
Version september_2017
Version september_2018
Qlik
Version april_2018
Version february_2018
Version february_2019
Version june_2017
Version june_2018
Version november_2017
Version november_2018
Version september_2017
Version september_2018

References (2)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.