HIGH
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS
Published Aug 26, 2019
8.1
HIGHCVSS 3.1
EPSS 14.31%
Description
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
Affected products
No data.
Configuration 1
AND
OR
- ≥ 10.5 · ≤ 10.5.18
- ≥ 2018.1 · ≤ 2018.1.15
- ≥ 2018.2 · ≤ 2018.12
- ≥ 2018.3 · ≤ 2018.3.9
- ≥ 2019.1 · ≤ 2019.1.6
- ≥ 2019.2 · ≤ 2019.2.2
Running on/with
- n/a
Configuration 2
AND
OR
- ≥ 10.2 · ≤ 10.2.23
- ≥ 10.3 · ≤ 10.3.23
- ≥ 10.4 · ≤ 10.4.19
- ≥ 10.5 · ≤ 10.5.18
- ≥ 2018.1 · ≤ 2018.1.15
- ≥ 2018.2 · ≤ 2018.12
- ≥ 2018.3 · ≤ 2018.3.9
- ≥ 2019.1 · ≤ 2019.1.6
- ≥ 2019.2 · ≤ 2019.2.2
Configuration 3
AND
OR
- ≥ 10.2 · ≤ 10.2.23
- ≥ 10.3 · ≤ 10.3.23
- ≥ 10.4 · ≤ 10.4.19
- ≥ 10.5 · ≤ 10.5.18
- ≥ 2018.1 · ≤ 2018.1.15
- ≥ 2018.2 · ≤ 2018.2.12
- ≥ 2018.3 · ≤ 2018.3.9
- ≥ 2019.1 · ≤ 2019.1.6
- ≥ 2019.2 · ≤ 2019.2.2
Configuration 4
AND
OR
- ≥ 10.2 · ≤ 10.2.23
- ≥ 10.3 · ≤ 10.3.23
- ≥ 10.4 · ≤ 10.4.19
- ≥ 10.5 · ≤ 10.5.18
- ≥ 2018.1 · ≤ 2018.1.15
- ≥ 2018.2 · ≤ 2018.2.12
- ≥ 2018.3 · ≤ 2018.3.9
- ≥ 2019.1 · ≤ 2019.1.6
- ≥ 2019.2 · ≤ 2019.2.2
Configuration 5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6589 Advisory
- https://github.com/minecrater/exploits/blob/master/TableauXXE.py x_refsource_MISCExploitThird Party Advisory
- https://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products | x_refsource_MISCVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6589 | Advisory | |
| https://github.com/minecrater/exploits/blob/master/TableauXXE.py | x_refsource_MISCExploitThird Party Advisory | |
| https://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 26, 2019
Updated Aug 5, 2024
Reserved Aug 26, 2019
Link CVE-2019-15637
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-6589 Assigner mitre
Published Aug 26, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-6589