CVE-2022-22128
Estado: ModificadaCrítica (9.8)—
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.51%
- Percentil entre todas las CVEs puntuadas: 74
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-22128",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-22128",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-13T20:10:33.423603Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@salesforce.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Tableau Server",
"versions": [
{
"status": "affected",
"version": "2022.1 - 2022.1.42021.4 - 2021.4.92021.3 - 2021.3.142021.2 - 2021.2.152021.1 - 2021.1.172020.4 - 2020.4.20"
}
]
}
]
}
],
"published": "2022-10-17T16:15:20.643",
"references": [
{
"url": "https://help.salesforce.com/s/articleView?id=000367027&type=1",
"tags": [
"Broken Link"
],
"source": "security@salesforce.com"
},
{
"url": "https://kb.tableau.com/articles/Issue/issue-affecting-tableau-server-administration-agent",
"tags": [
"Vendor Advisory"
],
"source": "nvd@nist.gov"
},
{
"url": "https://help.salesforce.com/s/articleView?id=000367027&type=1",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates."
},
{
"lang": "es",
"value": "Tableau ha detectado una vulnerabilidad de salto de rutas afectando al servicio de transferencia de archivos internos del agente de administración de Tableau Server y que podía permitir una ejecución de código remota. Tableau sólo soporta a las versiones del producto durante 24 meses después de su lanzamiento. Las versiones más antiguas han llegado al final de su vida útil y ya no reciben soporte. Tampoco son evaluadas para detectar posibles problemas de seguridad y no reciben actualizaciones de seguridad"
}
],
"lastModified": "2026-06-17T04:27:48.873",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1B9D0C7-8257-4646-ADDE-DC9F24C8A65F",
"versionEndIncluding": "2020.4.20",
"versionStartIncluding": "2020.4"
},
{
"criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC87E32E-AE8E-44DC-96E8-CDE5650A017B",
"versionEndIncluding": "2021.1.17",
"versionStartIncluding": "2021.1"
},
{
"criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9241C03F-5484-4A72-BA3D-5880127D0202",
"versionEndIncluding": "2021.2.15",
"versionStartIncluding": "2021.2"
},
{
"criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9550748E-38A1-4736-94D4-8A3E9534A287",
"versionEndIncluding": "2021.3.14",
"versionStartIncluding": "2021.3"
},
{
"criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D85EF9F-6A9F-4616-BE60-A92362A34160",
"versionEndIncluding": "2021.4.9",
"versionStartIncluding": "2021.4"
},
{
"criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16552215-FA84-4E48-AFDA-CCA7AF1E5C80",
"versionEndIncluding": "2022.1.4",
"versionStartIncluding": "2022.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@salesforce.com"
}