<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Critical Security fixes for Qlik Sense Enterprise for Windows (CVE-2023-48365) in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2120325</link>
    <description>&lt;H3 aria-level="2"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Executive Summary&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW112516660 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;A security issue in Qlik Sense Enterprise for Windows has been &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;identified,&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt; and patches have been made available. &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;If&lt;/SPAN&gt; &lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;successfully exploited, this vulnerability could lead to a compromise of the server running the Qlik Sense software, including unauthenticated remote code execution (RCE). &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;This resolves an incomplete fix for &lt;A href="https://community.qlik.com/t5/Support-Updates/Qlik-Sense-Enterprise-for-Windows-New-Security-Patches-Available/ba-p/2108549/" target="_blank" rel="noopener"&gt;CVE-2023-41265&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW112516660 BCX0" data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This issue was identified and responsibly reported to Qlik by Adam Crosser and Thomas Hendrickson of &lt;A href="https://www.praetorian.com/" target="_blank" rel="noopener"&gt;Praetorian&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ui-provider ee bgw bcy dlf dlg dlh dli dlj dlk dll dlm dln dlo dlp dlq dlr dls dlt dlu dlv dlw dlx dly dlz dma dmb dmc dmd dme dmf dmg dmh dmi dmj dmk"&gt;Qlik has received reports that this vulnerability may be being used by malicious actors. Customers should confirm they have applied the necessary patches outlined in this bulletin. If there are additional questions, customers may log a case with &lt;A href="https://community.qlik.com/t5/Support/ct-p/qlikSupport" target="_blank" rel="noopener"&gt;Qlik Support.&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Affected Software&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:40,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW224515680 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;All versions of Qlik Sense Enterprise for Windows &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW224515680 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;&lt;STRONG&gt;prior&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW224515680 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;to&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt; and including&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt; these releases are &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;impacted&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW224515680 BCX0" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;August 2023 Patch 1&lt;/LI&gt;
&lt;LI&gt;May 2023 Patch 5&lt;/LI&gt;
&lt;LI&gt;February 2023 Patch 9&lt;/LI&gt;
&lt;LI&gt;November 2022 Patch 11&lt;/LI&gt;
&lt;LI&gt;August 2022 Patch 13&lt;/LI&gt;
&lt;LI&gt;May 2022 Patch 15&lt;/LI&gt;
&lt;LI&gt;February 2022 Patch 14&lt;/LI&gt;
&lt;LI&gt;November 2021 Patch 16&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 aria-level="1"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Severity Rating&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW149037288 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0"&gt;Using the CVSS V3.1 scoring system (&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="Hyperlink SCXW149037288 BCX0" href="https://nvd.nist.gov/vuln-metrics/cvss" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN class="TextRun Underlined SCXW149037288 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0" data-ccp-charstyle="Hyperlink"&gt;https://nvd.nist.gov/vuln-metrics/cvss&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class="TextRun SCXW149037288 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0"&gt;), Qlik rates &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0"&gt;this&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0"&gt; severity as critical.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW149037288 BCX0" data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="1"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Vulnerability Details&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;CVE-2023-48365&lt;/STRONG&gt; (QB-21683) HTTP Tunneling vulnerability in Qlik Sense Enterprise for Windows&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Severity:&lt;/STRONG&gt;&lt;/FONT&gt; &lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;CVSS:3.1/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;AV:N&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;AC:L&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;PR:L&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;UI:N&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;/S:C/C:H/I:H/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;A:N&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt; (&lt;STRONG&gt;9.6 Critical&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Due to improper validation of HTTP Headers a remote attacker is able to elevate their privilege by tunnelling HTTP requests, allowing them to execute HTTP requests on the backend server hosting the repository application. This resolves an incomplete fix for CVE-2023-41265.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Recommendation&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;BLOCKQUOTE class="quote"&gt;These recommendations apply at the time of writing (September 2023). For up to date information, please refer to the &lt;A href="https://community.qlik.com/t5/Labels-page/bd-p/Category_Labels?categoryId=qlik-support-updates-blog&amp;amp;corenode=boards&amp;amp;labelText=Security+Notice&amp;amp;nodetype=boards" target="_blank" rel="noopener"&gt;Qlik Security Notice&lt;/A&gt; and review the latest &lt;A href="https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes" target="_blank" rel="noopener"&gt;Release Notes&lt;/A&gt; for your Qlik Sense version. Always update to the &lt;EM&gt;most&amp;nbsp;recent&lt;/EM&gt;&amp;nbsp;patch.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW153868444 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;Customers should&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt; upgrade Qlik Sense Enterprise for Windows to a version &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;containing&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt; fixes for these issues. &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;Fixes are available&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt; for the &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;following&lt;/SPAN&gt; &lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;versions&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW153868444 BCX0" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;November 2023 IR&lt;/LI&gt;
&lt;LI&gt;August 2023 Patch 2&lt;/LI&gt;
&lt;LI&gt;May 2023 Patch 6&lt;/LI&gt;
&lt;LI&gt;February 2023 Patch 10&lt;/LI&gt;
&lt;LI&gt;November 2022 Patch 12&lt;/LI&gt;
&lt;LI&gt;August 2022 Patch 14&lt;/LI&gt;
&lt;LI&gt;May 2022 Patch 16&lt;/LI&gt;
&lt;LI&gt;February 2022 Patch 15&lt;/LI&gt;
&lt;LI&gt;November 2021 Patch 17&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW203883433 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt;These patches include the fixes for &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt;previous&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt; issues &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt;CVE-2023-41266 and CVE-2023-41265&amp;nbsp;&lt;SPAN class="EOP SCXW203883433 BCX0" data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801" target="_blank" rel="noopener"&gt;link&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW203883433 BCX0" data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;All Qlik software can be downloaded from our official &lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Product-Downloads/tkb-p/Downloads" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Qlik Download page&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; (customer login required).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#999999"&gt;&lt;SPAN data-contrast="auto"&gt;Edit December 1st, 2023: Added November 2023 IR release to clarify it is&amp;nbsp;&lt;EM&gt;not&amp;nbsp;&lt;/EM&gt;affected&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2024 07:28:50 GMT</pubDate>
    <dc:creator>Sonja_Bauernfeind</dc:creator>
    <dc:date>2024-05-15T07:28:50Z</dc:date>
    <item>
      <title>Critical Security fixes for Qlik Sense Enterprise for Windows (CVE-2023-48365)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2120325</link>
      <description>&lt;H3 aria-level="2"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Executive Summary&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW112516660 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;A security issue in Qlik Sense Enterprise for Windows has been &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;identified,&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt; and patches have been made available. &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;If&lt;/SPAN&gt; &lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;successfully exploited, this vulnerability could lead to a compromise of the server running the Qlik Sense software, including unauthenticated remote code execution (RCE). &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;This resolves an incomplete fix for &lt;A href="https://community.qlik.com/t5/Support-Updates/Qlik-Sense-Enterprise-for-Windows-New-Security-Patches-Available/ba-p/2108549/" target="_blank" rel="noopener"&gt;CVE-2023-41265&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW112516660 BCX0"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW112516660 BCX0" data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This issue was identified and responsibly reported to Qlik by Adam Crosser and Thomas Hendrickson of &lt;A href="https://www.praetorian.com/" target="_blank" rel="noopener"&gt;Praetorian&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ui-provider ee bgw bcy dlf dlg dlh dli dlj dlk dll dlm dln dlo dlp dlq dlr dls dlt dlu dlv dlw dlx dly dlz dma dmb dmc dmd dme dmf dmg dmh dmi dmj dmk"&gt;Qlik has received reports that this vulnerability may be being used by malicious actors. Customers should confirm they have applied the necessary patches outlined in this bulletin. If there are additional questions, customers may log a case with &lt;A href="https://community.qlik.com/t5/Support/ct-p/qlikSupport" target="_blank" rel="noopener"&gt;Qlik Support.&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Affected Software&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:40,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW224515680 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;All versions of Qlik Sense Enterprise for Windows &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW224515680 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;&lt;STRONG&gt;prior&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW224515680 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;to&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt; and including&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt; these releases are &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;impacted&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW224515680 BCX0"&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW224515680 BCX0" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;August 2023 Patch 1&lt;/LI&gt;
&lt;LI&gt;May 2023 Patch 5&lt;/LI&gt;
&lt;LI&gt;February 2023 Patch 9&lt;/LI&gt;
&lt;LI&gt;November 2022 Patch 11&lt;/LI&gt;
&lt;LI&gt;August 2022 Patch 13&lt;/LI&gt;
&lt;LI&gt;May 2022 Patch 15&lt;/LI&gt;
&lt;LI&gt;February 2022 Patch 14&lt;/LI&gt;
&lt;LI&gt;November 2021 Patch 16&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 aria-level="1"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Severity Rating&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW149037288 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0"&gt;Using the CVSS V3.1 scoring system (&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="Hyperlink SCXW149037288 BCX0" href="https://nvd.nist.gov/vuln-metrics/cvss" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN class="TextRun Underlined SCXW149037288 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0" data-ccp-charstyle="Hyperlink"&gt;https://nvd.nist.gov/vuln-metrics/cvss&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class="TextRun SCXW149037288 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0"&gt;), Qlik rates &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0"&gt;this&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW149037288 BCX0"&gt; severity as critical.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW149037288 BCX0" data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="1"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Vulnerability Details&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;CVE-2023-48365&lt;/STRONG&gt; (QB-21683) HTTP Tunneling vulnerability in Qlik Sense Enterprise for Windows&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Severity:&lt;/STRONG&gt;&lt;/FONT&gt; &lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;CVSS:3.1/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;AV:N&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;AC:L&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;PR:L&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;UI:N&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt;/S:C/C:H/I:H/&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW135152680 BCX0"&gt;A:N&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW135152680 BCX0"&gt; (&lt;STRONG&gt;9.6 Critical&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Due to improper validation of HTTP Headers a remote attacker is able to elevate their privilege by tunnelling HTTP requests, allowing them to execute HTTP requests on the backend server hosting the repository application. This resolves an incomplete fix for CVE-2023-41265.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Recommendation&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;BLOCKQUOTE class="quote"&gt;These recommendations apply at the time of writing (September 2023). For up to date information, please refer to the &lt;A href="https://community.qlik.com/t5/Labels-page/bd-p/Category_Labels?categoryId=qlik-support-updates-blog&amp;amp;corenode=boards&amp;amp;labelText=Security+Notice&amp;amp;nodetype=boards" target="_blank" rel="noopener"&gt;Qlik Security Notice&lt;/A&gt; and review the latest &lt;A href="https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes" target="_blank" rel="noopener"&gt;Release Notes&lt;/A&gt; for your Qlik Sense version. Always update to the &lt;EM&gt;most&amp;nbsp;recent&lt;/EM&gt;&amp;nbsp;patch.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW153868444 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;Customers should&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt; upgrade Qlik Sense Enterprise for Windows to a version &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;containing&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt; fixes for these issues. &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;Fixes are available&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt; for the &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;following&lt;/SPAN&gt; &lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;versions&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW153868444 BCX0"&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW153868444 BCX0" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;November 2023 IR&lt;/LI&gt;
&lt;LI&gt;August 2023 Patch 2&lt;/LI&gt;
&lt;LI&gt;May 2023 Patch 6&lt;/LI&gt;
&lt;LI&gt;February 2023 Patch 10&lt;/LI&gt;
&lt;LI&gt;November 2022 Patch 12&lt;/LI&gt;
&lt;LI&gt;August 2022 Patch 14&lt;/LI&gt;
&lt;LI&gt;May 2022 Patch 16&lt;/LI&gt;
&lt;LI&gt;February 2022 Patch 15&lt;/LI&gt;
&lt;LI&gt;November 2021 Patch 17&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW203883433 BCX0" data-contrast="auto"&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt;These patches include the fixes for &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt;previous&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt; issues &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt;CVE-2023-41266 and CVE-2023-41265&amp;nbsp;&lt;SPAN class="EOP SCXW203883433 BCX0" data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801" target="_blank" rel="noopener"&gt;link&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW203883433 BCX0"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXW203883433 BCX0" data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;All Qlik software can be downloaded from our official &lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Product-Downloads/tkb-p/Downloads" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Qlik Download page&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; (customer login required).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#999999"&gt;&lt;SPAN data-contrast="auto"&gt;Edit December 1st, 2023: Added November 2023 IR release to clarify it is&amp;nbsp;&lt;EM&gt;not&amp;nbsp;&lt;/EM&gt;affected&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 07:28:50 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2120325</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-05-15T07:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Critical Security fixes for Qlik Sense Enterprise for Windows (CVE-pending)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/tac-p/2120510#M10221</link>
      <description>&lt;P&gt;&lt;SPAN&gt;For discussions and questions, comment directly on the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Support-Updates/Qlik-Sense-Enterprise-for-Windows-New-Security-Patches-Available/ba-p/2120330" target="_blank" rel="noopener"&gt;related blog post&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp; We will be monitoring it. Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 14:25:47 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/tac-p/2120510#M10221</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2023-09-20T14:25:47Z</dc:date>
    </item>
  </channel>
</rss>

