← Back

CVE-2023-48365

nvd nist
Published: Nov 15, 2023Modified: Oct 31, 2025CISA KEV

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: NVD

Description

Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265.

Affected (92)

Products: Qlik: Qlik Sense
1 product
Qlik Sense
Configuration A
92 vulnerable
Vulnerable SoftwareAffected Versions
Qlik
Version august_2022
Version august_2022 patch_10
Version august_2022 patch_11
Version august_2022 patch_12
Version august_2022 patch_13
Version august_2022 patch_1
Version august_2022 patch_2
Version august_2022 patch_3
Version august_2022 patch_4
Version august_2022 patch_5
Version august_2022 patch_6
Version august_2022 patch_7
Version august_2022 patch_8
Version august_2022 patch_9
Version august_2023
Version august_2023 patch_1
Version february_2022
Version february_2022 patch_10
Version february_2022 patch_11
Version february_2022 patch_12
Version february_2022 patch_13
Version february_2022 patch_14
Version february_2022 patch_1
Version february_2022 patch_2
Version february_2022 patch_3
Version february_2022 patch_4
Version february_2022 patch_5
Version february_2022 patch_6
Version february_2022 patch_7
Version february_2022 patch_8
Version february_2022 patch_9
Version february_2023
Version february_2023 patch_1
Version february_2023 patch_2
Version february_2023 patch_3
Version february_2023 patch_4
Version february_2023 patch_5
Version february_2023 patch_6
Version february_2023 patch_7
Version february_2023 patch_8
Version february_2023 patch_9
Version may_2022
Version may_2022 patch_10
Version may_2022 patch_11
Version may_2022 patch_12
Version may_2022 patch_13
Version may_2022 patch_14
Version may_2022 patch_15
Version may_2022 patch_1
Version may_2022 patch_2
Version may_2022 patch_3
Version may_2022 patch_4
Version may_2022 patch_5
Version may_2022 patch_6
Version may_2022 patch_7
Version may_2022 patch_8
Version may_2022 patch_9
Version may_2023
Version may_2023 patch_1
Version may_2023 patch_2
Version may_2023 patch_3
Version may_2023 patch_4
Version may_2023 patch_5
Version november_2021
Version november_2021 patch_10
Version november_2021 patch_11
Version november_2021 patch_12
Version november_2021 patch_13
Version november_2021 patch_14
Version november_2021 patch_15
Version november_2021 patch_16
Version november_2021 patch_1
Version november_2021 patch_2
Version november_2021 patch_3
Version november_2021 patch_4
Version november_2021 patch_5
Version november_2021 patch_6
Version november_2021 patch_7
Version november_2021 patch_8
Version november_2021 patch_9
Version november_2022
Version november_2022 patch_10
Version november_2022 patch_11
Version november_2022 patch_1
Version november_2022 patch_2
Version november_2022 patch_3
Version november_2022 patch_4
Version november_2022 patch_5
Version november_2022 patch_6
Version november_2022 patch_7
Version november_2022 patch_8
Version november_2022 patch_9

Timeline

No history available yet.