First published: Mon Aug 26 2019(Updated: )
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tableau Server | >=10.5<=10.5.18 | |
Tableau Server | >=2018.1<=2018.1.15 | |
Tableau Server | >=2018.2<=2018.12 | |
Tableau Server | >=2018.3<=2018.3.9 | |
Tableau Server | >=2019.1<=2019.1.6 | |
Tableau Server | >=2019.2<=2019.2.2 | |
Linux Kernel | ||
Tableau Server | >=10.2<=10.2.23 | |
Tableau Server | >=10.3<=10.3.23 | |
Tableau Server | >=10.4<=10.4.19 | |
Microsoft Windows Operating System | ||
Tableau Desktop | >=10.2<=10.2.23 | |
Tableau Desktop | >=10.3<=10.3.23 | |
Tableau Desktop | >=10.4<=10.4.19 | |
Tableau Desktop | >=10.5<=10.5.18 | |
Tableau Desktop | >=2018.1<=2018.1.15 | |
Tableau Desktop | >=2018.2<=2018.2.12 | |
Tableau Desktop | >=2018.3<=2018.3.9 | |
Tableau Desktop | >=2019.1<=2019.1.6 | |
Tableau Desktop | >=2019.2<=2019.2.2 | |
macOS | ||
Tableau Reader | >=10.2<=10.2.2 | |
Tableau Desktop | >=10.2<=10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15637 is a vulnerability in numerous Tableau products that allows for XML External Entity (XXE) attacks, leading to information disclosure or denial of service (DoS).
Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop are affected by CVE-2019-15637.
CVE-2019-15637 has a severity rating of 8.1 (high).
CVE-2019-15637 can be exploited through a malicious workbook, extension, or data source containing an XML External Entity (XXE) attack payload.
Yes, Tableau has released security updates to address the CVE-2019-15637 vulnerability. It is recommended to update to the latest version of Tableau products.