LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-48365: Qlik Sense HTTP Tunneling Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 13, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Feb 3, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-48365 to its Known Exploited Vulnerabilities catalog on Jan 13, 2025, with a federal patch deadline of Feb 3, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

CVE-2023-48365 is an HTTP tunneling vulnerability in Qlik Sense. It lets an attacker escalate privileges and send HTTP requests to the backend server that hosts the product. Because this class of flaw can give unauthorized access to the hosting environment and because it has been used in ransomware activity, teams running Qlik Sense should treat it as a high-priority item and confirm exact impact against the vendor advisory.

CISA notes that organizations should apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. The remainder of this guidance focuses on practical detection, remediation, and interim controls for IT and security teams.

How it works

The underlying weakness is classified as CWE-444. In plain terms, the product mishandles or inconsistently interprets certain HTTP requests, enabling an attacker to tunnel or smuggle requests that the backend server processes with elevated privileges. According to the CISA summary, a successful attacker can escalate privileges and execute HTTP requests on the backend server hosting Qlik Sense.

Exact request construction, authentication bypass details, and any required preconditions are not provided here; those must be confirmed against the vendor advisory. In general for this weakness class, the attacker typically needs network reachability to the Qlik Sense interface and may leverage crafted headers or request framing that the front-end and back-end components interpret differently. The result is unauthorized actions on the hosting server rather than simple data disclosure from the application itself.

Am I affected? How to find it in your systems

Qlik Sense is commonly deployed as a business-intelligence and analytics platform, often on Windows servers or in virtualized/cloud environments that serve dashboards and data models to internal users. It may sit behind reverse proxies, load balancers, or web application firewalls and frequently listens on standard HTTPS ports.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation package that addresses CVE-2023-48365, following the exact steps in the Qlik advisory. Confirm the fixed version or configuration change against that advisory before declaring systems remediated.

After patching, harden the deployment for this class of HTTP-handling weakness:

CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Document the remediation date and verification method for audit purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not eliminate it; schedule the official patch as soon as operationally feasible. If no viable mitigation exists, follow CISA guidance and discontinue use until a fix is available.

If your data may have been exposed

Actively exploited vulnerabilities of this type, including those with known ransomware use, frequently lead to broader compromise of the hosting server and any data or credentials accessible from it. If logs or other indicators suggest successful exploitation, treat the incident as a potential breach: isolate the system, preserve forensic evidence, and follow your incident-response plan. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether related credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQlik · Sense
WeaknessCWE-444
Added to CISA KEVJan 13, 2025
Federal patch deadlineFeb 3, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities