Vulnerabilities > CVE-2022-0564 - Information Exposure Through Discrepancy vulnerability in Qlik Sense

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
qlik
CWE-203

Summary

A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by the affected system to determine which accounts are valid user accounts. Affected systems are only vulnerable if they have LDAP configured.

Vulnerable Configurations

Part Description Count
Application
Qlik
1
OS
Microsoft
1

Common Weakness Enumeration (CWE)