Tableau
Tableau Server: vulnerabilidades y CVE
Tableau Server tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-52451 | Alta (8.5) | 0.21% | — | 22 ago 2025 | Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before… |
| CVE-2025-52450 | Media (6.5) | 0.41% | — | 22 ago 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create-data-source-from-file-upload modules) allows Absolute Path… |
| CVE-2025-26498 | Alta (7.3) | 0.27% | — | 22 ago 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) allows Absolute Path Traversal.This issue affects Tableau Server:… |
| CVE-2025-26497 | Alta (7.3) | 0.27% | — | 22 ago 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3,… |
| CVE-2025-26496 | Crítica (9.3) | 0.21% | — | 22 ago 2025 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau… |
| CVE-2025-52455 | Media (5.3) | 0.34% | — | 25 jul 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before… |
| CVE-2025-52454 | Alta (8.2) | 0.30% | — | 25 jul 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before… |
| CVE-2025-52453 | Alta (8.2) | 0.30% | — | 25 jul 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before… |
| CVE-2025-52452 | Alta (8.5) | 0.44% | — | 25 jul 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modules) allows Absolute Path Traversal.… |
| CVE-2025-52449 | Alta (8.5) | 0.26% | — | 25 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This… |
| CVE-2025-52448 | Alta (8.1) | 0.36% | — | 25 jul 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database… |
| CVE-2025-52447 | Alta (8.1) | 0.36% | — | 25 jul 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production… |
| CVE-2025-52446 | Alta (8) | 0.24% | — | 25 jul 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This… |
| CVE-2025-26495 | Alta (7.5) | 0.34% | — | 11 feb 2025 | Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before… |
| CVE-2025-26494 | Alta (7.7) | 0.57% | — | 11 feb 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5. |
| CVE-2022-22128 | Crítica (9.8) | 1.5% | — | 17 oct 2022 | Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24… |
| CVE-2022-22127 | Alta (7.2) | 1.1% | — | 25 may 2022 | Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity Store for managing users. The vulnerability allows a malicious site… |
| CVE-2021-1629 | Media (6.1) | 1.3% | — | 26 mar 2021 | Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users. |
| CVE-2020-6939 | Crítica (9.8) | 1.8% | — | 23 nov 2020 | Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users. If exploited, this could allow a malicious user to configure Site-Specific SAML settings and… |
| CVE-2020-6938 | Alta (7.5) | 1.2% | — | 8 jul 2020 | A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files. |
| CVE-2019-19719 | Media (6.1) | 22% | — | 11 dic 2019 | Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page. |
| CVE-2019-15637 | Alta (8.1) | 14% | — | 26 ago 2019 | Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau… |