CVE-2023-41266
KEV ransomwaremoderateUnauthenticated Path Traversal in Qlik Sense Enterprise for Windows
CISA: Qlik Sense Path Traversal Vulnerability
CVE-2023-41266 is a path traversal vulnerability (CWE-22) in Qlik Sense Enterprise for Windows that allows an unauthenticated remote attacker to generate an anonymous session. By sending crafted HTTP requests over the network, an attacker with no credentials can use that anonymous session to transmit requests to otherwise unauthorized endpoints (CVSS 3.1: 6.5). In documented campaigns, this access has been leveraged as an entry point for Cactus ransomware attacks against Qlik Sense deployments, and related reporting describes follow-on custom Linux malware delivery. Any organization running Qlik Sense Enterprise for Windows on the affected release tracks listed below is exposed, particularly when the server is internet-facing. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-12-07 with ransomware use flagged as known, and EPSS assigns an 84.8% probability of exploitation within 30 days.
What to do: Upgrade to August 2023 IR, or to the first fixed patch on your release track: May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13. Because ransomware exploitation is confirmed, prioritize patching any internet-exposed Qlik Sense servers and review logs for anonymous sessions and HTTP requests to unauthorized endpoints. Hunt for signs of Cactus ransomware activity on hosts that had the vulnerable version exposed.
| Qlik Sense Enterprise for Windows | May 2023 Patch 3 and earlier; February 2023 Patch 7 and earlier; November 2022 Patch 10 and earlier; August 2022 Patch 12 and earlier (fixed in August 2023 IR, |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.
- Affected
- Qlik Sense
- Required action
- Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- qlik
- Products
- qlik sense
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N