LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-41265: Qlik Sense HTTP Tunneling Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 7, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Dec 28, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-41265 to its Known Exploited Vulnerabilities catalog on Dec 7, 2023, with a federal patch deadline of Dec 28, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

CVE-2023-41265 is an HTTP tunneling vulnerability in Qlik Sense that lets an attacker escalate privileges and execute HTTP requests on the backend server hosting the software. Because it can give unauthorized control over the hosting server and has been tied to ransomware activity, organizations running Qlik Sense need to treat it as a high-priority exposure and confirm their status against the vendor advisory.

CISA lists the required action as applying remediations or mitigations per vendor instructions, or discontinuing use of the product if those are unavailable. The guidance below stays within the public facts for this CVE and the CWE-444 class; exact version ranges, patch identifiers, and exploit details must be verified with the vendor.

How it works

The underlying weakness is CWE-444, which covers inconsistent interpretation of HTTP requests—commonly called HTTP request smuggling or tunneling. In this class of flaw, an attacker crafts requests that different components of a system parse differently, allowing one request to be hidden inside or misrouted past another.

According to the CISA summary, the vulnerability in Qlik Sense specifically enables HTTP tunneling. An attacker who can reach the affected interface can escalate privileges and cause the backend server to execute HTTP requests of the attacker’s choosing. That capability can be used to reach internal resources, perform actions with elevated rights, or stage further compromise. No public exploit code or precise request format is supplied here; defenders should treat any unauthenticated or low-privilege access to the Qlik Sense HTTP endpoints as potentially sufficient for abuse until the vendor advisory confirms otherwise.

Am I affected? How to find it in your systems

Qlik Sense is business-intelligence and analytics software typically deployed on Windows or Linux servers, often behind reverse proxies or load balancers, and exposed to users via web interfaces. Inventory every instance by searching asset-management systems, software inventories, and network scans for Qlik Sense services, related processes, and listening ports associated with the product.

If version or configuration data is incomplete, treat the instance as potentially vulnerable until proven otherwise.

How to remediate

Patch first. Apply the vendor-supplied update or remediation that addresses CVE-2023-41265 exactly as described in the official Qlik advisory. After installation, verify the new version string and restart services according to vendor guidance.

Once the patch is confirmed, harden the deployment for this class of weakness:

If remediation is unavailable, CISA directs organizations to discontinue use of the product.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not replace the official patch.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to breaches and ransomware incidents. If logs or other indicators suggest successful exploitation, treat the environment as compromised: isolate affected hosts, preserve forensic evidence, and follow your incident-response process. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQlik · Sense
WeaknessCWE-444
Added to CISA KEVDec 7, 2023
Federal patch deadlineDec 28, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities