vendor:
Tableau Desktop
by:
Jarad Kopf
8.1
CVSS
HIGH
XML External Entity (XXE)
611
CWE
Product Name: Tableau Desktop
Affected Version From: See Tableau Advisory: https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products
Affected Version To: See Tableau Advisory: https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products
Patch Exists: YES
Related CWE: CVE-2019-15637
CPE: a:tableau:tableau_desktop
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
Tableau XXE
Tableau XXE is an XML External Entity (XXE) vulnerability in Tableau products. It allows an attacker to send malicious XML documents to a vulnerable Tableau server, which can then be used to read files from the server, or even execute arbitrary code. The vulnerability was reported to the vendor in July 2019, and a fix was released in August 2019.
Mitigation:
Tableau has released a patch to address this vulnerability. Users should update their Tableau products to the latest version to ensure they are protected.