CVE-2023-48365
Qlik Sense HTTP Tunneling Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.9
- EPSS
- 24.7% 백분위 97.6% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2025.02.03
- 공개일
- 2023.11.16
CISA KEV에 등록된 실제 악용 확인 취약점
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete...
공급사 Qlik
제품 Sense
영향 버전 n/a, august 2022, august 2023, february 2022, february 2023, may 2022, may 2023, november 2021, november 2022
수정 버전 공식 출처에서 확인 필요
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
조치 기한: 2025.02.03CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE CWE-444
KEV 등록일 2025.01.13
랜섬웨어 캠페인 사용 확인됨
CISA 비고 https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/tac-p/2120510 ; https://nvd.nist.gov/vuln/detail/CVE-2023-48365
EPSS 데이터 기준일 2026.06.27