Skip to content
COOEY

EXPOSURES › CVE-2023-48365

CVE-2023-48365

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-01-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-48365 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

Qlik Sense HTTP tunneling vulnerability allows privilege escalation and arbitrary HTTP requests on the backend server.

An HTTP tunneling flaw in Qlik Sense lets attackers escalate privileges and execute arbitrary HTTP requests on the backend server hosting the software. DIB organizations must patch this immediately as it is actively exploited in the wild and linked to ransomware campaigns, posing a severe compliance and operational risk.

Shame score — The vulnerability is actively exploited in the wild and linked to ransomware, indicating negligent patching and avoidable compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Qlik Cloud Government
Qlik Technologies Inc.
Authorized