community.tableau.com
https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products CVE-2019-15637
HIGH
tableau tableau_server Improper Restriction of XML External Entity Reference
Record summary
CVE-2019-15637 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit.
Description
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 25, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tableau_serverBrowse tableau / tableau_server | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBTableau - XML External EntityExploitDB exploitby Jarad KopfNot analyzed1 file
References
4github.com
https://github.com/minecrater/exploits/blob/master/TableauXXE.py nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-15637 packetstormsecurity.com
https://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html