CVE-2025-61138

7.5

Qlik · Sense Enterprise

Qlik Sense Enterprise version 14.212.13 contains an information disclosure vulnerability within the /dev-hub/ directory that allows unauthorized access to sensitive data.

Executive summary

An unauthenticated information disclosure vulnerability in Qlik Sense Enterprise version 14.212.13 poses a significant risk to data confidentiality.

Vulnerability

This is an information leak vulnerability occurring in the /dev-hub/ directory. The flaw is exploitable by an unauthenticated remote attacker with no user interaction required.

Business impact

The ability for an unauthenticated attacker to leak information from the server can lead to the exposure of proprietary data, system configuration details, or credentials. Given the CVSS score of 7.5, this high severity vulnerability represents a substantial risk to organizational confidentiality and could facilitate further exploitation of the environment.

Remediation

Immediate Action: Restrict access to the /dev-hub/ directory at the web server level until an official security patch is released by the vendor.

Proactive Monitoring: Review web server access logs for unusual requests targeting the /dev-hub/ endpoint, particularly those originating from unauthorized or external IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) rule to block or challenge all incoming requests to the /dev-hub/ path to prevent unauthorized directory traversal or information retrieval.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists on GitHub as documented in the provided references.

Analyst recommendation

Organizations running Qlik Sense Enterprise 14.212.13 must prioritize the protection of the affected directory immediately. Because the vulnerability allows unauthenticated access to system data, administrators should implement restrictive access controls without delay and monitor for any signs of unauthorized interaction with the development hub components.

Sources