Cyber Survival: CISA’s New Additions to Vulnerabilities Catalog

CISA adds two new vulnerabilities – Qlik Sense Path Traversal and Qlik Sense HTTP Tunneling – to its Known Exploited Vulnerabilities Catalog. With a BOD 22-01 directive, agencies are in a race against time to fix these issues, turning our cyber lives into a thrilling blockbuster.

Hot Take:

Key Points:

  • CISA added two new vulnerabilities, namely “Qlik Sense HTTP Tunneling Vulnerability” and “Qlik Sense Path Traversal Vulnerability,” to its Known Exploited Vulnerabilities Catalog.
  • These vulnerabilities pose a significant risk as they are common attack vectors for cybercriminals.
  • BOD 22-01 established the catalog as a living list of significant risk vulnerabilities and requires Federal Civilian Executive Branch agencies to address these vulnerabilities promptly.
  • While BOD 22-01 only applies to FCEB agencies, CISA recommends all organizations prioritize fixing these vulnerabilities as part of their vulnerability management practice.
  • CISA will continue to add vulnerabilities to the catalog that meet specified criteria.

The Back Channel:

Tags: BOD 22-01, cisa, CVE-2023-41265, CVE-2023-41266, Known Exploited Vulnerabilities Catalog, Qlik Sense vulnerabilities, vulnerability management