XML External Entity (XXE) Vulnerability in QlikTech Qlikview Allows SSRF Attacks and Arbitrary File Reading

XML External Entity (XXE) Vulnerability in QlikTech Qlikview Allows SSRF Attacks and Arbitrary File Reading

CVE-2015-3623 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:P/A:N

XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.

Learn more about our Cis Benchmark Audit For Server Software.