ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-61138
Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.

Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.

NVD description · AI analysis pending
7.5<1%
  • qlik qlik sense
CVE-2023-48365
HTTP Request Smuggling/Tunneling in Qlik Sense Allows Privilege Escalation

Qlik Sense contains an HTTP tunneling flaw (CWE-444, inconsistent interpretation of HTTP requests, i.e., HTTP request smuggling) in which the application's tunneling component and the backend server hosting the software disagree about HTTP request boundaries. An attacker triggers it by sending crafted HTTP requests through the tunneling mechanism of an affected Qlik Sense deployment. Exploitation lets the attacker escalate privileges and execute HTTP requests against the backend server, reaching internal services and interfaces that should only be accessible to the application. Any organization running an affected Qlik Sense deployment is exposed, with internet-facing instances at greatest risk. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-01-13 with ransomware use known, and EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Apply Qlik's remediation for CVE-2023-48365 per the vendor's security instructions, or discontinue use of the product if mitigations are unavailable (CISA KEV required action). Prioritize internet-exposed Qlik Sense servers, and given known ransomware use, hunt for indicators such as unexpected requests arriving at the backend server, anomalous authentication activity, and lateral movement originating from the Qlik host.

9.924% KEV ransomware
  • Qlik Sense
large≈tens of thousands of enterprise deployments, with on the order of a few thousand Qlik Sense servers exposed to the internet
CVE-2023-41265
+1 in the same advisory: …41266
HTTP Request Tunneling Privilege Escalation in Qlik Sense Enterprise for Windows

CVE-2023-41265 is an HTTP request tunneling flaw (CWE-444) in Qlik Sense Enterprise for Windows that lets a remote attacker tunnel additional HTTP requests inside a single raw HTTP request, causing those requests to be executed by the backend server hosting the repository application. Because the tunneled requests are processed in a trusted backend context, the attacker, who needs only low-privileged access according to the CVSS score, achieves privilege elevation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.9 critical, scope changed). All Windows releases up to and including May 2023 Patch 3, February 2023 Patch 7, November 2022 Patch 10, and August 2022 Patch 12 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-07 with known ransomware use, EPSS places it in the 100th percentile (88.2% probability of exploitation within 30 days), and reporting ties active exploitation to CACTUS ransomware campaigns as well as 1-day attacks delivering NerbianRAT Linux malware. No public proof-of-concept is known, but exploitation is ongoing, making unpatched, especially internet-exposed, Qlik Sense servers a priority for defenders.

Do: Upgrade Qlik Sense Enterprise for Windows to the fixed release for your track: May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13; the August 2023 IR also contains the fix. Per CISA's KEV required action, apply vendor remediations or discontinue use of the product if remediation is unavailable. Given active CACTUS ransomware exploitation of Qlik flaws, prioritize patching internet-exposed servers, restrict access to trusted networks, and check patched and unpatched instances for signs of compromise.

9.9
group max
88% KEV ransomware
  • Qlik Sense Enterprise for Windows May 2023 Patch 3 and earlier (fixed in May 2023 Patch 4)
  • Qlik Sense Enterprise for Windows February 2023 Patch 7 and earlier (fixed in February 2023 Patch 8)
  • Qlik Sense Enterprise for Windows November 2022 Patch 10 and earlier (fixed in November 2022 Patch 11)
  • +1 more
largeroughly 10,000–100,000 installations worldwide, with likely thousands of internet-exposed Qlik Sense servers
CVE-2022-42248
QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.

QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.

NVD description · AI analysis pending
5.4<1%
  • qlik qlikview
CVE-2021-41989
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.

Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.

NVD description · AI analysis pending
7.8<1%
  • qlik qlikview
CVE-2021-41988
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.

Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.

NVD description · AI analysis pending
7.8<1%
  • qlik nprinting designer
CVE-2021-36761
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.

The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.

NVD description · AI analysis pending
5.31%
  • qlik qlik sense
CVE-2022-0564
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts.

A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by the affected system to determine which accounts are valid user accounts. Affected systems are only vulnerable if they have LDAP configured. The affected URI is /internal_forms_authentication/ the response time of the form is longer if the supplied user does not exists and shorter if the user exists.

NVD description · AI analysis pending
5.31%
  • qlik qlik sense
CVE-2019-11628
An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2;

An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3, June 2018 Patch 3, September 2018 Patch 4, November 2018 Patch 4, or February 2019 Patch 2. An authenticated user may be able to bypass intended file-read restrictions via crafted Browser requests.

NVD description · AI analysis pending
6.5<1%
  • qlik qlikview server
  • qlik qlik analytics
  • qlik qlik sense