CVE-2023-48365
Qlik Sense vulnerability analysis and mitigation

Overview

Qlik Sense Enterprise for Windows before August 2023 Patch 2 contains a critical vulnerability (CVE-2023-48365) that allows unauthenticated remote code execution. This vulnerability, also known as QB-21683, exists due to improper validation of HTTP headers, enabling remote attackers to elevate their privileges through HTTP request tunneling. The vulnerability is particularly notable as it represents an incomplete fix for a previous vulnerability (CVE-2023-41265). The issue affects multiple versions of Qlik Sense Enterprise for Windows and was discovered by Adam Crosser and Thomas Hendrickson of Praetorian (Praetorian Blog).

Technical details

The vulnerability has received a CVSS v3.1 base score of 9.9 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The technical root cause involves improper validation of HTTP headers, specifically in how the system handles the Transfer-Encoding and Content-Length headers. Attackers can bypass the security mechanism by using modified values like 'tchunked' instead of 'chunked' in the Transfer-Encoding header, which the backend server interprets as valid chunked encoding while bypassing front-end validation (Praetorian Blog).

Impact

If successfully exploited, this vulnerability could lead to a complete compromise of the server running the Qlik Sense software. The impact includes potential unauthenticated remote code execution, allowing attackers to execute arbitrary commands on the affected system. The vulnerability has been observed being actively exploited in ransomware attacks (Arctic Wolf).

Exploitability

The vulnerability is being actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Arctic Wolf has reported multiple incident response cases where ransomware groups have exploited this vulnerability for initial access. The exploitation requires no user interaction and can be performed remotely (CISA Alert).

Mitigation and workarounds

Organizations should upgrade to the fixed versions: August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, or November 2021 Patch 17. These patches include fixes for both this vulnerability and the previous related vulnerabilities CVE-2023-41265 and CVE-2023-41266 (Qlik Advisory).

Community reactions

CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog on January 13, 2025, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate it by February 3, 2025. The agency strongly urges all organizations to prioritize patching this vulnerability as part of their vulnerability management practice (CISA Alert).

Additional resources


SourceThis report was generated using AI

Related Qlik Sense vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-48365CRITICAL9.9
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
YesNoNov 15, 2023
CVE-2023-41265CRITICAL9.9
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
YesNoAug 29, 2023
CVE-2025-61138HIGH7.5
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
NoYesNov 20, 2025
CVE-2023-41266MEDIUM6.5
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
YesNoAug 29, 2023
CVE-2021-36761MEDIUM5.3
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
NoNoJun 21, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management