Required CVE Record Information
Description
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
7.1 | HIGH | 3.0 | CVSS:3.0/AC:L/AV:N/A:L/C:H/I:N/PR:L/S:U/UI:N |
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products x_transferred
- https://github.com/minecrater/exploits/blob/master/TableauXXE.py x_transferred
- https://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html x_transferred