CVE-2019-15637
high · 8.1Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
8.1
CVSS
14.3%
EPSS (exploit prob.)
96th
EPSS percentile
2019-08-26
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Weaknesses
CWE-611
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| tableau | tableau_server | >= 10.5, <= 10.5.18 |
| tableau | tableau_server | >= 2018.1, <= 2018.1.15 |
| tableau | tableau_server | >= 2018.2, <= 2018.12 |
| tableau | tableau_server | >= 2018.3, <= 2018.3.9 |
| tableau | tableau_server | >= 2019.1, <= 2019.1.6 |
| tableau | tableau_server | >= 2019.2, <= 2019.2.2 |
| linux | linux_kernel | all versions |
| tableau | tableau_server | >= 10.2, <= 10.2.23 |
| tableau | tableau_server | >= 10.3, <= 10.3.23 |
| tableau | tableau_server | >= 10.4, <= 10.4.19 |
| tableau | tableau_server | >= 10.5, <= 10.5.18 |
| tableau | tableau_server | >= 2018.1, <= 2018.1.15 |
| tableau | tableau_server | >= 2018.2, <= 2018.12 |
| tableau | tableau_server | >= 2018.3, <= 2018.3.9 |
| tableau | tableau_server | >= 2019.1, <= 2019.1.6 |
| tableau | tableau_server | >= 2019.2, <= 2019.2.2 |
| microsoft | windows | all versions |
| tableau | tableau_desktop | >= 10.2, <= 10.2.23 |
| tableau | tableau_desktop | >= 10.3, <= 10.3.23 |
| tableau | tableau_desktop | >= 10.4, <= 10.4.19 |
| tableau | tableau_desktop | >= 10.5, <= 10.5.18 |
| tableau | tableau_desktop | >= 2018.1, <= 2018.1.15 |
| tableau | tableau_desktop | >= 2018.2, <= 2018.2.12 |
| tableau | tableau_desktop | >= 2018.3, <= 2018.3.9 |
| tableau | tableau_desktop | >= 2019.1, <= 2019.1.6 |
| tableau | tableau_desktop | >= 2019.2, <= 2019.2.2 |
| apple | macos | all versions |
| tableau | tableau_desktop | >= 10.2, <= 10.2.23 |
| tableau | tableau_desktop | >= 10.3, <= 10.3.23 |
| tableau | tableau_desktop | >= 10.4, <= 10.4.19 |
| tableau | tableau_desktop | >= 10.5, <= 10.5.18 |
| tableau | tableau_desktop | >= 2018.1, <= 2018.1.15 |
| tableau | tableau_desktop | >= 2018.2, <= 2018.2.12 |
| tableau | tableau_desktop | >= 2018.3, <= 2018.3.9 |
| tableau | tableau_desktop | >= 2019.1, <= 2019.1.6 |
| tableau | tableau_desktop | >= 2019.2, <= 2019.2.2 |
| microsoft | windows | all versions |
| tableau | tableau_reader | >= 10.2, <= 10.2.2 |
| apple | macos | all versions |
| microsoft | windows | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products
- https://github.com/minecrater/exploits/blob/master/TableauXXE.py
- https://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html
- https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products
- https://github.com/minecrater/exploits/blob/master/TableauXXE.py
- https://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-15637