← Back

CVE-2023-41265

Published: Aug 29, 2023Modified: Oct 31, 2025CISA KEV

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: NVD

Description

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

Affected (36)

Products: Qlik: Qlik Sense
1 product
Qlik Sense
Configuration A
36 vulnerable
Vulnerable SoftwareAffected Versions
Qlik
Version august_2022
Version august_2022 patch_10
Version august_2022 patch_11
Version august_2022 patch_12
Version august_2022 patch_1
Version august_2022 patch_2
Version august_2022 patch_3
Version august_2022 patch_4
Version august_2022 patch_5
Version august_2022 patch_6
Version august_2022 patch_7
Version august_2022 patch_8
Version august_2022 patch_9
Version february_2023
Version february_2023 patch_1
Version february_2023 patch_2
Version february_2023 patch_3
Version february_2023 patch_4
Version february_2023 patch_5
Version february_2023 patch_6
Version february_2023 patch_7
Version may_2023
Version may_2023 patch3
Version may_2023 patch_1
Version may_2023 patch_2
Version november_2022
Version november_2022 patch_10
Version november_2022 patch_1
Version november_2022 patch_2
Version november_2022 patch_3
Version november_2022 patch_4
Version november_2022 patch_5
Version november_2022 patch_6
Version november_2022 patch_7
Version november_2022 patch_8
Version november_2022 patch_9

Timeline

No history available yet.