{"cveID":"CVE-2023-41265","vendorProject":"Qlik","product":"Sense","vulnerabilityName":"Qlik Sense HTTP Tunneling Vulnerability","dateAdded":"2023-12-07","shortDescription":"Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.","requiredAction":"Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.","dueDate":"2023-12-28","knownRansomwareCampaignUse":"Known","notes":"https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801;  https://nvd.nist.gov/vuln/detail/CVE-2023-41265","cwes":["CWE-444"],"year":2023,"state":"unmapped","stale_reasons":[],"mappings":[],"techniques":[],"mapping_types":[],"has_exploitation_technique":false,"mapping_attack_versions":[],"mapping_domains":[],"sigma_coverage":null,"sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}