CVE-2015-3623: SSRF
Published Sep 16, 2015
·Updated
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.
Affected Software
1 affected component
Qlik Qlikview<=11.20
Event History
Sep 16, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3623?
CVE-2015-3623 has a medium severity due to its potential for server-side request forgery (SSRF) and arbitrary file reading.
2
How do I fix CVE-2015-3623?
To fix CVE-2015-3623, upgrade QlikView to version 11.20 SR12 or later.
3
What type of attack does CVE-2015-3623 enable?
CVE-2015-3623 enables remote attackers to conduct server-side request forgery (SSRF) attacks.
4
What software is affected by CVE-2015-3623?
CVE-2015-3623 affects QlikTech QlikView versions up to and including 11.20 SR11.
5
What is the impact of CVE-2015-3623 on the system?
The impact of CVE-2015-3623 includes unauthorized file access and potential system compromise through SSRF.