ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Qlik Sense flaws to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2023-41265CVE-2023-41266

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-41265
+1 in the same advisory: …41266
HTTP Request Tunneling Privilege Escalation in Qlik Sense Enterprise for Windows

CVE-2023-41265 is an HTTP request tunneling flaw (CWE-444) in Qlik Sense Enterprise for Windows that lets a remote attacker tunnel additional HTTP requests inside a single raw HTTP request, causing those requests to be executed by the backend server hosting the repository application. Because the tunneled requests are processed in a trusted backend context, the attacker, who needs only low-privileged access according to the CVSS score, achieves privilege elevation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.9 critical, scope changed). All Windows releases up to and including May 2023 Patch 3, February 2023 Patch 7, November 2022 Patch 10, and August 2022 Patch 12 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-07 with known ransomware use, EPSS places it in the 100th percentile (88.2% probability of exploitation within 30 days), and reporting ties active exploitation to CACTUS ransomware campaigns as well as 1-day attacks delivering NerbianRAT Linux malware. No public proof-of-concept is known, but exploitation is ongoing, making unpatched, especially internet-exposed, Qlik Sense servers a priority for defenders.

Do: Upgrade Qlik Sense Enterprise for Windows to the fixed release for your track: May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13; the August 2023 IR also contains the fix. Per CISA's KEV required action, apply vendor remediations or discontinue use of the product if remediation is unavailable. Given active CACTUS ransomware exploitation of Qlik flaws, prioritize patching internet-exposed servers, restrict access to trusted networks, and check patched and unpatched instances for signs of compromise.

9.9
group max
88% KEV ransomware
  • Qlik Sense Enterprise for Windows May 2023 Patch 3 and earlier (fixed in May 2023 Patch 4)
  • Qlik Sense Enterprise for Windows February 2023 Patch 7 and earlier (fixed in February 2023 Patch 8)
  • Qlik Sense Enterprise for Windows November 2022 Patch 10 and earlier (fixed in November 2022 Patch 11)
  • +1 more
largeroughly 10,000–100,000 installations worldwide, with likely thousands of internet-exposed Qlik Sense servers
Full article289 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 11, 2023

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds two Qlik Sense vulnerabilities to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Qlik Sense vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

Below is the list of the issues added to the catalog:

  • CVE-2023-41265 (CVSS score 9.6)- Qlik Sense HTTP Tunneling Vulnerability: Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
  • CVE-2023-41266 (CVSS score 8.2) – Qlik Sense Path Traversal Vulnerability: Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.

Researchers at cybersecurity firm Praetorian discovered the two vulnerabilities in August 2023. The popular researcher Kevin Beaumont pointed out threat actors started exploiting a full exploit chain published by Praetorian.

Researchers from Arctic Wolf also observed threat actors exploiting both flaws in attacks carried out by the Cactus ransomware gang.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix these vulnerabilities by December 28, 2023.

Last week the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualcomm vulnerabilities to its KEV catalog.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/155615/security/cisa-qlik-sense-flaws-known-exploited-vulnerabilities-catalog.html