File-Read Restriction Bypass in QlikView Server and Qlik Sense Enterprise
CVE-2019-11628

8.2HIGH

Key Information:

Vendor

Qlik

Vendor
CVE Published:
1 May 2019

What is CVE-2019-11628?

An issue within QlikView Server and Qlik Sense Enterprise allows authenticated users to bypass file-read restrictions through specially crafted browser requests. This vulnerability impacts specific versions of QlikView Server prior to designated service releases and Qlik Sense Enterprise installations lacking several important patches. Users are encouraged to update to the latest versions and apply the necessary patches to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-11628 : File-Read Restriction Bypass in QlikView Server and Qlik Sense Enterprise