vendor:
QlikView
by:
Alex Haynes
7,5
CVSS
HIGH
Improper Restriction of XML External Entity Reference [CWE-611]
611
CWE
Product Name: QlikView
Affected Version From: v11.20 SR11
Affected Version To: v11.20 SR4
Patch Exists: YES
Related CWE: CVE-2015-3623
CPE: a:qlik:qlikview
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Qlikview blind XXE security vulnerability
The Qlikview platform is vulnerable to XML External Entity (XXE) vulnerabilities. More specifically, the platform is susceptible to DTD parameter injections, which are also 'blind' as the server feeds back no visual response. These vulnerabilities can be exploited to force Server Side Request Forgeries (SSRF)in multiple protocols, as well as reading and extracting arbitrary files on the server directly.
Mitigation:
Ensure that the application is not vulnerable to XXE attacks by disabling external entity references and DTDs.