Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-15637


Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.


Published

2019-08-26T17:15:12.710

Last Modified

2024-11-21T04:29:10.270

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tableau tableau_server ≤ 10.5.18 Yes
Application tableau tableau_server ≤ 2018.1.15 Yes
Application tableau tableau_server ≤ 2018.12 Yes
Application tableau tableau_server ≤ 2018.3.9 Yes
Application tableau tableau_server ≤ 2019.1.6 Yes
Application tableau tableau_server ≤ 2019.2.2 Yes
Operating System linux linux_kernel - No
Application tableau tableau_server ≤ 10.2.23 Yes
Application tableau tableau_server ≤ 10.3.23 Yes
Application tableau tableau_server ≤ 10.4.19 Yes
Application tableau tableau_server ≤ 10.5.18 Yes
Application tableau tableau_server ≤ 2018.1.15 Yes
Application tableau tableau_server ≤ 2018.12 Yes
Application tableau tableau_server ≤ 2018.3.9 Yes
Application tableau tableau_server ≤ 2019.1.6 Yes
Application tableau tableau_server ≤ 2019.2.2 Yes
Operating System microsoft windows - No
Application tableau tableau_desktop ≤ 10.2.23 Yes
Application tableau tableau_desktop ≤ 10.3.23 Yes
Application tableau tableau_desktop ≤ 10.4.19 Yes
Application tableau tableau_desktop ≤ 10.5.18 Yes
Application tableau tableau_desktop ≤ 2018.1.15 Yes
Application tableau tableau_desktop ≤ 2018.2.12 Yes
Application tableau tableau_desktop ≤ 2018.3.9 Yes
Application tableau tableau_desktop ≤ 2019.1.6 Yes
Application tableau tableau_desktop ≤ 2019.2.2 Yes
Operating System apple macos - No
Application tableau tableau_desktop ≤ 10.2.23 Yes
Application tableau tableau_desktop ≤ 10.3.23 Yes
Application tableau tableau_desktop ≤ 10.4.19 Yes
Application tableau tableau_desktop ≤ 10.5.18 Yes
Application tableau tableau_desktop ≤ 2018.1.15 Yes
Application tableau tableau_desktop ≤ 2018.2.12 Yes
Application tableau tableau_desktop ≤ 2018.3.9 Yes
Application tableau tableau_desktop ≤ 2019.1.6 Yes
Application tableau tableau_desktop ≤ 2019.2.2 Yes
Operating System microsoft windows - No
Application tableau tableau_reader ≤ 10.2.2 Yes
Operating System apple macos - No
Operating System microsoft windows - No
Application tableau tableau_public_desktop ≤ 10.2.2 Yes
Operating System apple macos - No
Operating System microsoft windows - No

References