Skip to main content

Critical Security Updates Released for Qlik Sense Enterprise for Windows

The vulnerabilities known as CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365 could be used together to achieve unauthenticated RCE

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The vulnerabilities known as CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365 could be used together to achieve unauthenticated RCE


Threat details

Introduction

Qlik Community has released a knowledge base article regarding three vulnerabilities affecting Qlik Sense Enterprise for Windows. The critical vulnerability tracked as CVE-2023-41265 is a HTTP tunneling vulnerability, which could allow an attacker to escalate privileges when successfully exploited.

The high severity vulnerability known as CVE-2023-41266 is a path traversal vulnerability. An unauthenticated, remote attacker could generate an anonymous session, leading to HTTP requests to unauthorised endpoints.

Importantly, the two vulnerabilities can be chained together by an attacker to compromise the server running the Qlik Sense software, with the ability to achieve unauthenticated remote code execution (RCE).

The third vulnerability, CVE-2023-48365, is rated as critical, and exists due to an incomplete fix for CVE-2023-41265. Exploitation in the wild of these three vulnerabilities has been observed.

Exploitation in the wild of CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365

Following the release of full technical details of these exploits, threat actors have been observed exploiting these vulnerabilities in the wild.


Threat updates

Date Update
8 Dec 2023 Exploitation in the wild has been observed

This cyber alert has been updated to reflect these changes.

4 Sep 2023 Technical details of exploit have been published

This cyber alert has been updated to reflect this change.


Remediation advice

Affected organisations are encouraged to read the Qlik Community advisories Critical Security fixes for Qlik Sense Enterprise for Windows (CVE-2023-41266, CVE-2023-41265) and Critical Security fixes for Qlik Sense Enterprise for Windows (CVE-2023-48365) and to update Qlik Sense Enterprise for Windows to a remediated version below.

  • November 2023 IR
  • August 2023 Patch 2
  • May 2023 Patch 6
  • February 2023 Patch 10
  • November 2022 Patch 12
  • August 2022 Patch 14
  • May 2022 Patch 16
  • February 2022 Patch 15
  • November 2021 Patch 17


CVE Vulnerabilities

Last edited: 8 December 2023 10:18 am