PT-2022-6509 · Qlik · Qlikview

Giulio Garzia

·

Published

2022-10-03

·

Updated

2023-03-13

·

CVE-2022-42248

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions QlikView version 12.60.2
Description The issue is related to the QvsViewClient functionality of the QlikView analytical platform, where the structure of web pages is not properly protected when creating interactive objects. This can be exploited by a remote attacker to perform cross-site scripting attacks by sending specially crafted POST requests. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For QlikView version 12.60.2, consider disabling the QvsViewClient functionality until a patch is available to prevent potential cross-site scripting attacks. Restrict access to the QvsViewClient module to minimize the risk of exploitation. Avoid using the QvsViewClient functionality in the affected API endpoints until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-01821
CVE-2022-42248

Affected Products

Qlikview