target entity

Sense

3 source-linked records in the current knowledge graph.

high

CVE-2023-48365: Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-48365EPSS 24.7%QlikSense
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41266: Qlik Sense Path Traversal Vulnerability

Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-41266EPSS 82.6%QlikSense
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41265: Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-41265EPSS 85.0%QlikSense
CISA KEV ↗ · unattributed attribution