Lucene search

K
cve[email protected]CVE-2019-11628
HistoryMay 01, 2019 - 3:29 a.m.

CVE-2019-11628

2019-05-0103:29:00
CWE-917
web.nvd.nist.gov
46
cve-2019-11628
qlikview
qlik sense
authenticated user
file-read restrictions
security vulnerability
patch levels

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.6%

An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3, June 2018 Patch 3, September 2018 Patch 4, November 2018 Patch 4, or February 2019 Patch 2. An authenticated user may be able to bypass intended file-read restrictions via crafted Browser requests.

Affected configurations

NVD
Node
qlikqlikview_serverMatch11.20service_release_1
OR
qlikqlikview_serverMatch11.20service_release_10
OR
qlikqlikview_serverMatch11.20service_release_11
OR
qlikqlikview_serverMatch11.20service_release_12
OR
qlikqlikview_serverMatch11.20service_release_13
OR
qlikqlikview_serverMatch11.20service_release_14
OR
qlikqlikview_serverMatch11.20service_release_15
OR
qlikqlikview_serverMatch11.20service_release_16
OR
qlikqlikview_serverMatch11.20service_release_17
OR
qlikqlikview_serverMatch11.20service_release_2
OR
qlikqlikview_serverMatch11.20service_release_3
OR
qlikqlikview_serverMatch11.20service_release_4
OR
qlikqlikview_serverMatch11.20service_release_5
OR
qlikqlikview_serverMatch11.20service_release_6
OR
qlikqlikview_serverMatch11.20service_release_7
OR
qlikqlikview_serverMatch11.20service_release_8
OR
qlikqlikview_serverMatch11.20service_release_9
OR
qlikqlikview_serverMatch12.00
OR
qlikqlikview_serverMatch12.10service_release_1
OR
qlikqlikview_serverMatch12.10service_release_2
OR
qlikqlikview_serverMatch12.10service_release_3
OR
qlikqlikview_serverMatch12.10service_release_4
OR
qlikqlikview_serverMatch12.10service_release_5
OR
qlikqlikview_serverMatch12.10service_release_6
OR
qlikqlikview_serverMatch12.10service_release_7
OR
qlikqlikview_serverMatch12.10service_release_8
OR
qlikqlikview_serverMatch12.10service_release_9
OR
qlikqlikview_serverMatch12.20service_release_1
OR
qlikqlikview_serverMatch12.20service_release_2
OR
qlikqlikview_serverMatch12.20service_release_3
OR
qlikqlikview_serverMatch12.20service_release_4
OR
qlikqlikview_serverMatch12.30service_release_1
Node
qlikqlik_analyticsMatchapril_2018
OR
qlikqlik_analyticsMatchfebruary_2018
OR
qlikqlik_analyticsMatchfebruary_2019
OR
qlikqlik_analyticsMatchjune_2017
OR
qlikqlik_analyticsMatchjune_2018
OR
qlikqlik_analyticsMatchnovember_2017
OR
qlikqlik_analyticsMatchnovember_2018
OR
qlikqlik_analyticsMatchseptember_2017
OR
qlikqlik_analyticsMatchseptember_2018
OR
qlikqlik_senseMatchapril_2018enterprise
OR
qlikqlik_senseMatchfebruary_2018enterprise
OR
qlikqlik_senseMatchfebruary_2019enterprise
OR
qlikqlik_senseMatchjune_2017enterprise
OR
qlikqlik_senseMatchjune_2018enterprise
OR
qlikqlik_senseMatchnovember_2017enterprise
OR
qlikqlik_senseMatchnovember_2018enterprise
OR
qlikqlik_senseMatchseptember_2017enterprise
OR
qlikqlik_senseMatchseptember_2018enterprise

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.6%

Related for CVE-2019-11628