tableau kayıtları
tableau üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %59,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-6939İstismar yok | Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users.tableau · tableau server | Kritik9,8 | — | %1,8 | 23 Kas 2020 |
39İzleyin | CVE-2022-22128İstismar yok | Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could tableau · tableau server · CWE-22 | Kritik9,8 | — | %1,5 | 17 Eki 2022 |
37İzleyin | CVE-2025-26496İstismar yok | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux tableau · tableau server · CWE-843 | Kritik9,3 | — | %0,2 | 22 Ağu 2025 |
36İzleyin | CVE-2019-15637Kavram kanıtı | Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a tableau · tableau server · CWE-611 | Yüksek8,1 | — | %14,3 | 26 Ağu 2019 |
34İzleyin | CVE-2025-52452İstismar yok | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux tableau · tableau server · CWE-22 | Yüksek8,5 | — | %0,4 | 25 Tem 2025 |
34İzleyin | CVE-2025-52449İstismar yok | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service motableau · tableau server · CWE-434 | Yüksek8,5 | — | %0,3 | 25 Tem 2025 |
34İzleyin | CVE-2025-52451İstismar yok | Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modtableau · tableau server · CWE-20 | Yüksek8,5 | — | %0,2 | 22 Ağu 2025 |
32İzleyin | CVE-2025-52447İstismar yok | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc commantableau · tableau server · CWE-639 | Yüksek8,1 | — | %0,4 | 25 Tem 2025 |
32İzleyin | CVE-2025-52448İstismar yok | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modutableau · tableau server · CWE-639 | Yüksek8,1 | — | %0,4 | 25 Tem 2025 |
32İzleyin | CVE-2025-52453İstismar yok | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Ltableau · tableau server · CWE-918 | Yüksek8,2 | — | %0,3 | 25 Tem 2025 |
32İzleyin | CVE-2025-52454İstismar yok | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resourctableau · tableau server · CWE-918 | Yüksek8,2 | — | %0,3 | 25 Tem 2025 |
32İzleyin | CVE-2025-52446İstismar yok | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Itableau · tableau server · CWE-639 | Yüksek8,0 | — | %0,2 | 25 Tem 2025 |
31İzleyin | CVE-2019-19719İstismar yok | Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.tableau · tableau server · CWE-79 | Orta6,1 | — | %22,0 | 11 Ara 2019 |
30İzleyin | CVE-2020-6938İstismar yok | A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow atableau · tableau server · CWE-532 | Yüksek7,5 | — | %1,2 | 8 Tem 2020 |
30İzleyin | CVE-2025-26494İstismar yok | Server Side Request Forgery vulnerability in Tableau Servertableau · tableau server · CWE-918 | Yüksek7,7 | — | %0,6 | 11 Şub 2025 |
30İzleyin | CVE-2025-26495İstismar yok | Sensitive Data Exposure in Tableau Servertableau · tableau server · CWE-312 | Yüksek7,5 | — | %0,3 | 11 Şub 2025 |
29İzleyin | CVE-2025-26498İstismar yok | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo mtableau · tableau server · CWE-434 | Yüksek7,3 | — | %0,3 | 22 Ağu 2025 |
29İzleyin | CVE-2025-26497İstismar yok | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Abtableau · tableau server · CWE-434 | Yüksek7,3 | — | %0,3 | 22 Ağu 2025 |
28İzleyin | CVE-2022-22127İstismar yok | Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity tableau · tableau server | Yüksek7,2 | — | %1,1 | 25 May 2022 |
26İzleyin | CVE-2025-52450İstismar yok | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux tableau · tableau server · CWE-22 | Orta6,5 | — | %0,4 | 22 Ağu 2025 |
24İzleyin | CVE-2021-1629İstismar yok | Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.tableau · tableau server · CWE-601 | Orta6,1 | — | %1,3 | 26 Mar 2021 |
21İzleyin | CVE-2025-52455İstismar yok | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Locatiotableau · tableau server · CWE-918 | Orta5,3 | — | %0,3 | 25 Tem 2025 |
- CVE-2020-693940Planlayın
Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users.
KritikCVSS 9,8İstismar yokEPSS %2tableau · tableau server23 Kas 2020
- CVE-2022-2212839İzleyin
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could
KritikCVSS 9,8İstismar yokEPSS %2tableau · tableau server17 Eki 2022
- CVE-2025-2649637İzleyin
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux
KritikCVSS 9,3İstismar yokEPSS %0tableau · tableau server22 Ağu 2025
- CVE-2019-1563736İzleyin
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a
YüksekCVSS 8,1Kavram kanıtıEPSS %14tableau · tableau server26 Ağu 2019
- CVE-2025-5245234İzleyin
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux
YüksekCVSS 8,5İstismar yokEPSS %0tableau · tableau server25 Tem 2025
- CVE-2025-5244934İzleyin
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service mo
YüksekCVSS 8,5İstismar yokEPSS %0tableau · tableau server25 Tem 2025
- CVE-2025-5245134İzleyin
Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload mod
YüksekCVSS 8,5İstismar yokEPSS %0tableau · tableau server22 Ağu 2025
- CVE-2025-5244732İzleyin
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc comman
YüksekCVSS 8,1İstismar yokEPSS %0tableau · tableau server25 Tem 2025
- CVE-2025-5244832İzleyin
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modu
YüksekCVSS 8,1İstismar yokEPSS %0tableau · tableau server25 Tem 2025
- CVE-2025-5245332İzleyin
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource L
YüksekCVSS 8,2İstismar yokEPSS %0tableau · tableau server25 Tem 2025
- CVE-2025-5245432İzleyin
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resourc
YüksekCVSS 8,2İstismar yokEPSS %0tableau · tableau server25 Tem 2025
- CVE-2025-5244632İzleyin
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows I
YüksekCVSS 8,0İstismar yokEPSS %0tableau · tableau server25 Tem 2025
- CVE-2019-1971931İzleyin
Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
OrtaCVSS 6,1İstismar yokEPSS %22tableau · tableau server11 Ara 2019
- CVE-2020-693830İzleyin
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow a
YüksekCVSS 7,5İstismar yokEPSS %1tableau · tableau server8 Tem 2020
- CVE-2025-2649430İzleyin
Server Side Request Forgery vulnerability in Tableau Server
YüksekCVSS 7,7İstismar yokEPSS %1tableau · tableau server11 Şub 2025
- CVE-2025-2649530İzleyin
Sensitive Data Exposure in Tableau Server
YüksekCVSS 7,5İstismar yokEPSS %0tableau · tableau server11 Şub 2025
- CVE-2025-2649829İzleyin
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo m
YüksekCVSS 7,3İstismar yokEPSS %0tableau · tableau server22 Ağu 2025
- CVE-2025-2649729İzleyin
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Ab
YüksekCVSS 7,3İstismar yokEPSS %0tableau · tableau server22 Ağu 2025
- CVE-2022-2212728İzleyin
Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity
YüksekCVSS 7,2İstismar yokEPSS %1tableau · tableau server25 May 2022
- CVE-2025-5245026İzleyin
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux
OrtaCVSS 6,5İstismar yokEPSS %0tableau · tableau server22 Ağu 2025
- CVE-2021-162924İzleyin
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
OrtaCVSS 6,1İstismar yokEPSS %1tableau · tableau server26 Mar 2021
- CVE-2025-5245521İzleyin
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Locatio
OrtaCVSS 5,3İstismar yokEPSS %0tableau · tableau server25 Tem 2025