« Volver al listado

CVE-2025-52455

Estado: AnalizadaMedia (5.3)—

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-52455",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-52455",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-25T20:34:52.928277Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@salesforce.com",
      "affectedData": [
        {
          "vendor": "Salesforce",
          "modules": [
            "EPS Server"
          ],
          "product": "Tableau Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2025.1.3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2024.2.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2023.3.19",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Windows",
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-25T19:15:41.263",
  "references": [
    {
      "url": "https://help.salesforce.com/s/articleView?id=005105043&type=1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@salesforce.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@salesforce.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19."
    },
    {
      "lang": "es",
      "value": "Server-Side Request Forgery (SSRF) en Salesforce Tableau Server para Windows y Linux (módulos EPS Server) permite la suplantación de la ubicación de recursos. Este problema afecta a Tableau Server: versiones anteriores a 2025.1.3, 2024.2.12 y 2023.3.19. "
    }
  ],
  "lastModified": "2026-06-17T09:36:31.657",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19541292-4BD4-4BD5-AA68-3836ECC1EBE0",
              "versionEndExcluding": "2023.3.19"
            },
            {
              "criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AC0483E-569A-497C-BB94-D129FACC17D5",
              "versionEndExcluding": "2024.2.12",
              "versionStartIncluding": "2024.2"
            },
            {
              "criteria": "cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E78711C-389B-4E20-9623-8B0CF6BBCAC8",
              "versionEndExcluding": "2025.1.3",
              "versionStartIncluding": "2025.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@salesforce.com"
}