EXPOSURES › CVE-2023-48365
CVE-2023-48365
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQlik Sense HTTP tunneling vulnerability allows privilege escalation and arbitrary HTTP requests on the backend server.
An HTTP tunneling flaw in Qlik Sense lets attackers escalate privileges and execute arbitrary HTTP requests on the backend server hosting the software. DIB organizations must patch this immediately as it is actively exploited in the wild and linked to ransomware campaigns, posing a severe compliance and operational risk.
Shame score — The vulnerability is actively exploited in the wild and linked to ransomware, indicating negligent patching and avoidable compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
| PRODUCT | STATUS |
|---|---|
| Qlik Cloud Government Qlik Technologies Inc. |
Authorized |