Improper access control in Qlik Sense Enterprise for Windows - CVE-2024-55580

 

Improper access control in Qlik Sense Enterprise for Windows - CVE-2024-55580

Published: June 11, 2025


Vulnerability identifier: #VU111081
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-55580
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper access restrictions. A remote attacker on the local network can bypass implemented security restrictions and execute arbitrary code on the server. 


Affected software

Qlik Sense Enterprise for Windows

How to mitigate CVE-2024-55580

Install updates from vendor's website.

Qlik Sense Enterprise for Windows - addressed in versions August 2023 Patch 16, November 2024, May 2024 Patch 10, February 2024 Patch 14, February 2023 Patch 15, November 2023 Patch 16, May 2023 Patch 18

External References

Related Security Bulletins