Improper authentication in Qlik Alerting - CVE-2025-31509

 

Improper authentication in Qlik Alerting - CVE-2025-31509

Published: June 11, 2025


Vulnerability identifier: #VU111079
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31509
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the authentication process. A remote non-authenticated attacker can bypass basic authentication and gain unauthorized access to the server.

Successful exploitation of the vulnerability may result in full system compromise. 


Affected software

Qlik Alerting

How to mitigate CVE-2025-31509

Install updates from vendor's website.

Qlik Alerting - update to July 2023 Service Release 2

External References

Related Security Bulletins