CVE-2019-15637: XEE
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15637?
CVE-2019-15637 is a vulnerability in numerous Tableau products that allows for XML External Entity (XXE) attacks, leading to information disclosure or denial of service (DoS).
Which Tableau products are affected by CVE-2019-15637?
Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop are affected by CVE-2019-15637.
What is the severity of CVE-2019-15637?
CVE-2019-15637 has a severity rating of 8.1 (high).
How can CVE-2019-15637 be exploited?
CVE-2019-15637 can be exploited through a malicious workbook, extension, or data source containing an XML External Entity (XXE) attack payload.
Is there a fix available for CVE-2019-15637?
Yes, Tableau has released security updates to address the CVE-2019-15637 vulnerability. It is recommended to update to the latest version of Tableau products.