CVE-2023-41265 Details
Description
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.
A privilege escalation vulnerability has been identified in Qlik Sense Enterprise for Windows, affecting several versions through May 2023 Patch 3, February 2023 Patch 7, November 2022 Patch 10, and August 2022 Patch 12. This vulnerability allows remote attackers to tunnel HTTP requests in the raw HTTP headers, executing those requests on the backend server hosting the application repository.
Users are advised to upgrade Qlik Sense Enterprise for Windows to a version that includes the security patch. The fixed versions are August 2023 Initial Release, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13. Qlik software can be downloaded from the official Qlik Download page, with customer login required.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 29, 2023References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Qlik Sense HTTP Tunneling Vulnerability | Dec 7, 2023 | Dec 28, 2023 | Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| qlik qlik sense | august_2022 - august_2022 patch_1 august_2022 patch_10 august_2022 patch_11 august_2022 patch_12 august_2022 patch_2 august_2022 patch_3 august_2022 patch_4 august_2022 patch_5 august_2022 patch_6 august_2022 patch_7 august_2022 patch_8 august_2022 patch_9 february_2023 - february_2023 patch_1 february_2023 patch_2 february_2023 patch_3 february_2023 patch_4 february_2023 patch_5 february_2023 patch_6 february_2023 patch_7 may_2023 - may_2023 patch_1 may_2023 patch_2 may_2023 patch3 november_2022 - november_2022 patch_1 november_2022 patch_10 november_2022 patch_2 november_2022 patch_3 november_2022 patch_4 november_2022 patch_5 november_2022 patch_6 november_2022 patch_7 november_2022 patch_8 november_2022 patch_9 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 31, 2025 | Modified Analysis | [email protected] |
| Oct 30, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Nov 29, 2024 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 8, 2023 | Initial Analysis | [email protected] |