CVE-2014-1204

Tableau Server 8.0.x-8.0.6 and 8.1.x-8.1.1 - Authenticated SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-1204. PoCs published by Trustwave's SpiderLabs.

AI-analyzed exploit summary This advisory describes a blind SQL injection vulnerability in Tableau Server versions 8.1.X before 8.1.2 and 8.0.X before 8.0.7. The vulnerability allows authenticated or guest users to inject arbitrary SQL into the backend Oracle database via the 'modified_after' or 'modified_before' parameters.

Description

SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be exploited by unauthenticated remote attackers if the guest user is enabled.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Trustwave's SpiderLabs · textwebappswindows
https://www.exploit-db.com/exploits/31578

This advisory describes a blind SQL injection vulnerability in Tableau Server versions 8.1.X before 8.1.2 and 8.0.X before 8.0.7. The vulnerability allows authenticated or guest users to inject arbitrary SQL into the backend Oracle database via the 'modified_after' or 'modified_before' parameters.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Tableau Server 8.1.X before 8.1.2 and 8.0.X before 8.0.7
Auth required
Prerequisites: Authenticated user or guest access enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Release Notes x_refsource_confirm
http://www.tableausoftware.com/support/releases/8.0.7
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/102568
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/31578
Vendor Advisory x_refsource_confirm
http://www.tableausoftware.com/support/releases/812
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90730
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56620
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029706
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65171

Scores

EPSS 0.0430
EPSS Percentile 89.9%

Details

CWE
CWE-89
Status published
Products (9)
tableausoftware/tableau_server 8.0
tableausoftware/tableau_server 8.0.1
tableausoftware/tableau_server 8.0.2
tableausoftware/tableau_server 8.0.3
tableausoftware/tableau_server 8.0.4
tableausoftware/tableau_server 8.0.5
tableausoftware/tableau_server 8.0.6
tableausoftware/tableau_server 8.1
tableausoftware/tableau_server 8.1.1
Published Jan 31, 2014
Tracked Since Feb 18, 2026