PT-2019-12435 · Qlik · Qlik Analytics Platform+2
Published
2019-05-01
·
Updated
2020-08-24
·
CVE-2019-11628
CVSS v3.1
8.2
High
| Vector | AC:H/AV:N/A:N/C:H/I:H/PR:L/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
QlikView Server versions prior to 11.20 SR19
QlikView Server versions 12.00 through 12.10 before 12.10 SR11
QlikView Server versions 12.20 through 12.20 before SR9
QlikView Server versions 12.30 through 12.30 before SR2
Qlik Sense Enterprise (affected versions not specified)
Qlik Analytics Platform (affected versions not specified)
Description
An issue allows an authenticated user to bypass intended file-read restrictions via crafted browser requests.
Recommendations
For QlikView Server versions prior to 11.20 SR19, apply the February 2018 Patch 4 or later to resolve the issue.
For QlikView Server versions 12.00 through 12.10 before 12.10 SR11, apply the April 2018 Patch 3 or later to resolve the issue.
For QlikView Server versions 12.20 through 12.20 before SR9, apply the June 2018 Patch 3 or later to resolve the issue.
For QlikView Server versions 12.30 through 12.30 before SR2, apply the September 2018 Patch 4 or later to resolve the issue.
For Qlik Sense Enterprise and Qlik Analytics Platform, apply the November 2018 Patch 4 or February 2019 Patch 2 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qlik Analytics Platform
Qlik Sense Enterprise
Qlikview Server