
🚨 CVE-2023-48365 : CRITICAL BI PLATFORM RCE ALERT 🚨 A critical unauthenticated remote code execution vulnerability has been disclosed in Qlik Sense Enterprise for Windows, exploitable via malicious HTTP header injection. Attackers can bypass authentication entirely and execute commands with SYSTEM privileges on exposed analytics servers. Risk Severity: - Critical (CVSS 9.6, active exploitation, public proof-of-concept available) Impact: - Unauthenticated remote code execution (SYSTEM-level) - Complete compromise of Qlik Sense servers - Full access to sensitive analytics data and connected data sources - Ransomware deployment and persistent backdoors - Credential harvesting and lateral movement within enterprise networks - Business disruption and regulatory exposure Root Cause: - CWE-93 (Improper Neutralization of CRLF Sequences in HTTP Headers). Qlik Sense fails to sanitize carriage return and line feed characters in user-controllable HTTP headers, allowing request splitting and tunneling that bypasses authentication controls and exposes privileged internal APIs. Attackers can: - Inject malicious CRLF sequences via the `X-Qlik-User` header - Bypass proxy authentication and tunnel internal API requests - Upload malicious applications or extensions via `/qrs/` endpoints - Execute arbitrary PowerShell or CMD commands as SYSTEM - Exfiltrate enterprise analytics data and credentials - Establish persistence within Qlik services Are You Affected? - Vulnerable: Qlik Sense Enterprise for Windows versions prior to patched releases (Aug 2023 Patch 2 and earlier streams) - Scope: Internet-facing Qlik Sense deployments on Windows servers Immediate Action Required: - Update: Apply the latest cumulative patch for your Qlik Sense version immediately or upgrade to the latest supported release - Mitigation: Restrict external access to ports 4244 and 4248, require VPN access, and deploy WAF rules blocking CRLF sequences in HTTP headers - Audit:Monitor for abnormal `X-Qlik-User` headers, unauthorized `/qrs/` API calls, and child processes spawned by QlikSenseServiceDispatcher.exe Business intelligence platforms concentrate your most sensitive data. Treat exposed Qlik Sense servers as high-value breach targets and patch immediately. 🛡️ #ostorlabCVE
Post summary
A critical, unauthenticated RCE in Qlik Sense Enterprise with public PoC and active exploitation is reported; immediate patching and mitigations are advised.
