6.4
CVSSv2

CVE-2015-3623

Published: 16/09/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

XML external entity (XXE) vulnerability in QlikTech Qlikview prior to 11.20 SR12 allows remote malicious users to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.

Vulnerable Product Search on Vulmon Subscribe to Product

qlik qlikview

Exploits

Exploit Title: Qlikview blind XXE security vulnerability Product: Qlikview Vulnerable Versions: v1120 SR11 and previous versions Tested Version: v1120 SR4 Advisory Publication: 08/09/2015 Latest Update: 08/09/2015 Vulnerability Type: Improper Restriction of XML External Entity Reference [CWE-611] CVE Reference: CVE-2015-3623 Credit: Alex Haynes ...
The Qlikview platform is vulnerable to XML External Entity (XXE) vulnerabilities More specifically, the platform is susceptible to DTD parameter injections, which are also "blind" as the server feeds back no visual response These vulnerabilities can be exploited to force Server Side Request Forgeries (SSRF)in multiple protocols, as well as readin ...