XML External Entity Vulnerability in QlikTech Qlikview
CVE-2015-3623

Currently unrated

Key Information:

Vendor

Qlik

Status
Vendor
CVE Published:
16 September 2015

What is CVE-2015-3623?

An XML External Entity (XXE) vulnerability exists in QlikTech's Qlikview prior to version 11.20 SR12. This flaw allows remote attackers to perform server-side request forgery (SSRF) attacks by crafting malicious XML data sent to AccessPoint.aspx, enabling them to gain unauthorized access to sensitive files within the server environment.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.