A vulnerability in Qlik Sense Enterprise on Windows could...
Moderate severity
Unreviewed
Published
Feb 22, 2022
to the GitHub Advisory Database
•
Updated Jan 2, 2024
Description
Published by the National Vulnerability Database
Feb 21, 2022
Published to the GitHub Advisory Database
Feb 22, 2022
Last updated
Jan 2, 2024
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by the affected system to determine which accounts are valid user accounts. Affected systems are only vulnerable if they have LDAP configured.
References