The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two Qlik Sense software vulnerabilities to its list of Known Exploited Vulnerabilities ( KEV).

The two vulnerabilities are the following:
CVE-2023-41265 (CVSS score 9.6/10): This is a Qlik Sense HTTP Tunneling Vulnerability. The vulnerability allows an attacker to gain elevated privileges and execute HTTP requests on the backend server hosting the software.
CVE-2023-41266 (CVSS score 8.2/10): This is a Qlik Sense Path Traversal Vulnerability. This vulnerability allows a remote, unauthenticated attacker to create an anonymous session by sending malicious HTTP requests. The anonymous session could allow the attacker to send further requests to unauthorized endpoints.
Researchers at cybersecurity firm Praetorian discovered the two vulnerabilities in Qlik Sense in August. Researcher Kevin Beaumont noted that threat actors began exploiting an exploit chain published by Praetorian to carry out their attacks.
See also: Apple fixes zero-day vulnerabilities in older iPhones
Researchers from Arctic Wolf also identified attacks exploiting these vulnerabilities carried out by the Cactus.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, federal agencies FCEB must immediately update their systems to fix the two Qlik Sense vulnerabilities and protect their networks from attacks.
Experts also recommend that private organizations review the KEV List and take action to fix vulnerabilities contained in this list that threaten infrastructure .
CISA has mandated federal agencies to fix these vulnerabilities by December 28, 2023.
See also: Backup Migration: WordPress plugin vulnerable to critical vulnerability
Last week, the US (CISA) added Qualcomm vulnerabilities to its KEV list.

To address the vulnerabilities that appear on the CISA list, regularly updating systems is the key protection measure.
Additionally, organizations and companies must take security measures to prevent and detect attacks. These include using strong passwords ,limiting access to sensitive information , and monitoring network activity for early detection of “anomalies.”
See also: Atlassian: Fixes critical vulnerabilities in many products
Additionally, user education is an important security. Users and employees should be trained to recognize and avoid malicious files and emails ,as well as to prevent the sharing of sensitive information.
Finally, collaborating with security and analyzing threats is an important measure to address the vulnerabilities reported by CISA. Continuous threat monitoring and vulnerability analysis help strengthen the security of systems.
Source: securityaffairs.com
