CVE-2015-3623: Qlik Qlikview

Medium severity, CVSS 6.4. EPSS: 15.8% chance of exploitation in the next 30 days.

XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.

Affected products

  • Qlik Qlikview: up to and including 11.20

Published 2015-09-16. Last modified 2026-06-17.