A security issue in Qlik Sense Enterprise for Windows has been identified, and patches have been made available. If successfully exploited, this vulnerability could lead to a compromise of the server running the Qlik Sense software, including remote code execution (RCE).
This issue was responsibly disclosed to Qlik and no reports of it being maliciously exploited have been received.
Affected Software
All versions of Qlik Sense Enterprise for Windows priorto and including these releases are impacted:
Due to improper input validation, a remote attacker with existing privileges is able to elevate them to the internal system role, which in turns allows them to execute commands on the server.
Resolution
Recommendation
Customers should upgrade Qlik Sense Enterprise for Windows to a version containing fixes for these issues. Fixes are available for the followingversions:
May 2024 Initial Release
February 2024 Patch 4
November 2023 Patch 9
August 2023 Patch 14
May 2023 Patch 16
February 2023 Patch 14
November 2022 Patch 14
August 2022 Patch 17
May 2022 Patch 18
All Qlik software can be downloaded from our official Qlik Download page (customer login required).
Credit
This issue was identified and responsibly reported to Qlik by Daniel Zajork.
Edited 20th of May 2024: Added recently assigned CVE number.