Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-36077

CVSS 8.8 · High EPSS 0.55% · P68
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-36077

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands on the server. This affects February 2024 Patch 3 (14.173.3 through 14.173.7), November 2023 Patch 8 (14.159.4 through 14.159.13), August 2023 Patch 13 (14.139.3 through 14.139.20), May 2023 Patch 15 (14.129.3 through 14.129.22), February 2023 Patch 13 (14.113.1 through 14.113.18), November 2022 Patch 13 (14.97.2 through 14.97.18), August 2022 Patch 16 (14.78.3 through 14.78.23), and May 2022 Patch 17 (14.67.7 through 14.67.31). This has been fixed in May 2024 (14.187.4), February 2024 Patch 4 (14.173.8), November 2023 Patch 9 (14.159.14), August 2023 Patch 14 (14.139.21), May 2023 Patch 16 (14.129.23), February 2023 Patch 14 (14.113.19), November 2022 Patch 14 (14.97.19), August 2022 Patch 17 (14.78.25), and May 2022 Patch 18 (14.67.34).
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Qlik Sense 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Qlik Sense是美国Qlik公司的一个应用程序。允许用户为本地和离线使用创建可视化、图表、交互式仪表板和分析应用程序。 Qlik Sense Enterprise 14.187.4之前版本存在安全漏洞,该漏洞源于允许远程攻击者将权限提升至内部系统角色从而执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2024-36077

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-36077

登录查看更多情报信息。

Same Patch Batch · n/a · 2024-05-22 · 34 CVEs total

CVE-2024-35362Ecshop 安全漏洞
CVE-2024-33221ASUS BIOS Flash Driver 安全漏洞
CVE-2024-33222ASUS ATSZIO Driver 安全漏洞
CVE-2024-33223ASUS GPUTweak II 安全漏洞
CVE-2024-33224Realtek Semiconductor Corp Realtek lO Driver 安全漏洞
CVE-2024-33225Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver 安全漏洞
CVE-2024-33226Wistron Corporation TBT Force Power Control 安全漏洞
CVE-2024-33227Nicomsoft WinI2C/DDC 安全漏洞
CVE-2024-33228Insyde Software Corp SEG Windows Driver 安全漏洞
CVE-2024-33220ASUS AI Suite 安全漏洞
CVE-2024-29392Silverpeas 安全漏洞
CVE-2024-34448Ghost Foundation Ghost 安全漏洞
CVE-2024-29421xmedcon 安全漏洞
CVE-2024-31617Litespeed Technologie OpenLiteSpeed 安全漏洞
CVE-2024-25738Open Library Foundation VuFind 安全漏洞
CVE-2024-25737Open Library Foundation VuFind 安全漏洞
CVE-2024-35627TileServer GL 安全漏洞
CVE-2024-35551idccms 安全漏洞
CVE-2024-33219ASUS SABERTOOTH X99 Driver 安全漏洞
CVE-2024-33218ASUS USB 安全漏洞

Showing top 20 of 34 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2024-36077

No comments yet


Leave a comment