EXPOSURES › CVE-2023-41265
CVE-2023-41265
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQlik Sense HTTP tunneling vulnerability allows privilege escalation and arbitrary HTTP requests on the backend server.
An attacker can escalate privileges and execute arbitrary HTTP requests on the backend server hosting Qlik Sense. DIB orgs must patch this immediately as it is actively exploited in the wild and linked to ransomware, posing a severe compliance and operational risk.
Shame score — The vulnerability is actively exploited in the wild, linked to ransomware, and allows privilege escalation, indicating severe negligence and avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
| PRODUCT | STATUS |
|---|---|
| Qlik Cloud Government Qlik Technologies Inc. |
Authorized |