vendor:
QlikView
by:
Luis Martinez
7.5
CVSS
HIGH
Denial of Service (DoS) Local
CWE
Product Name: QlikView
Affected Version From: 12.50.20000.0
Affected Version To: 12.50.20000.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro x64
2020
QlikView 12.50.20000.0 – ‘FTP Server Address’ Denial of Service (PoC)
This exploit allows an attacker to crash the QlikView 12.50.20000.0 software by sending a specially crafted FTP server address. By pasting a large buffer of 'A' characters into the 'FTP Server Address' field, the software crashes, resulting in a denial of service.
Mitigation:
Apply the latest patch or update from the vendor to fix the crash issue.