Inconsistent interpretation of HTTP requests in Qlik Sense Enterprise for Windows - CVE-2023-48365

 

Inconsistent interpretation of HTTP requests in Qlik Sense Enterprise for Windows - CVE-2023-48365

Published: November 30, 2023


Vulnerability identifier: #VU83603
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-48365
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests caused by an incomplete fix for #VU80193 (CVE-2023-41265). A remote authenticated user can elevate their privileges within the application by tunneling HTTP requests.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Qlik Sense Enterprise for Windows

How to mitigate CVE-2023-48365

Install updates from vendor's website.

Qlik Sense Enterprise for Windows - addressed in versions August 2022 Patch 14, August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, February 2022 Patch 15, May 2022 Patch 16, November 2021 Patch 17

External References

Related Security Bulletins