
Cloud Vulnerability DB
A community-led vulnerabilities database
Qlik Sense Enterprise for Windows before August 2023 Patch 2 contains a critical vulnerability (CVE-2023-48365) that allows unauthenticated remote code execution. This vulnerability, also known as QB-21683, exists due to improper validation of HTTP headers, enabling remote attackers to elevate their privileges through HTTP request tunneling. The vulnerability is particularly notable as it represents an incomplete fix for a previous vulnerability (CVE-2023-41265). The issue affects multiple versions of Qlik Sense Enterprise for Windows and was discovered by Adam Crosser and Thomas Hendrickson of Praetorian (Praetorian Blog).
The vulnerability has received a CVSS v3.1 base score of 9.9 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The technical root cause involves improper validation of HTTP headers, specifically in how the system handles the Transfer-Encoding and Content-Length headers. Attackers can bypass the security mechanism by using modified values like 'tchunked' instead of 'chunked' in the Transfer-Encoding header, which the backend server interprets as valid chunked encoding while bypassing front-end validation (Praetorian Blog).
If successfully exploited, this vulnerability could lead to a complete compromise of the server running the Qlik Sense software. The impact includes potential unauthenticated remote code execution, allowing attackers to execute arbitrary commands on the affected system. The vulnerability has been observed being actively exploited in ransomware attacks (Arctic Wolf).
The vulnerability is being actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Arctic Wolf has reported multiple incident response cases where ransomware groups have exploited this vulnerability for initial access. The exploitation requires no user interaction and can be performed remotely (CISA Alert).
Organizations should upgrade to the fixed versions: August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, or November 2021 Patch 17. These patches include fixes for both this vulnerability and the previous related vulnerabilities CVE-2023-41265 and CVE-2023-41266 (Qlik Advisory).
CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog on January 13, 2025, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate it by February 3, 2025. The agency strongly urges all organizations to prioritize patching this vulnerability as part of their vulnerability management practice (CISA Alert).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."