CVE-2019-11628: High severity qlikview server vulnerability
An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3, June 2018 Patch 3, September 2018 Patch 4, November 2018 Patch 4, or February 2019 Patch 2. An authenticated user may be able to bypass intended file-read restrictions via crafted Browser requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11628?
CVE-2019-11628 has a severity rating of medium, indicating potential security risks.
How do I fix CVE-2019-11628?
To fix CVE-2019-11628, apply the latest patches for QlikView Server and Qlik Sense Enterprise as specified in the vendor's advisory.
Which versions of Qlik are affected by CVE-2019-11628?
CVE-2019-11628 affects QlikView Server versions prior to 11.20 SR19 and various versions of Qlik Sense prior to the specified patch levels.
What types of installations are impacted by CVE-2019-11628?
CVE-2019-11628 impacts installations of QlikView Server, Qlik Sense Enterprise, and Qlik Analytics Platform that are not updated to the necessary patch versions.
Is there a workaround for CVE-2019-11628?
There are no known workarounds for CVE-2019-11628; the only solution is to apply the required patches.