IT

Tracker / CVE-2019-15637

CVE-2019-15637

High 8.1

Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.

Affected products and versions

tableau tableau_desktop · 10.2 → 10.2.23
tableau tableau_desktop · 10.3 → 10.3.23
tableau tableau_desktop · 10.4 → 10.4.19
tableau tableau_desktop · 10.5 → 10.5.18
tableau tableau_desktop · 2018.1 → 2018.1.15
tableau tableau_desktop · 2018.2 → 2018.2.12
tableau tableau_desktop · 2018.3 → 2018.3.9
tableau tableau_desktop · 2019.1 → 2019.1.6
tableau tableau_desktop · 2019.2 → 2019.2.2
tableau tableau_public_desktop · 10.2 → 10.2.2
tableau tableau_reader · 10.2 → 10.2.2
tableau tableau_server · 10.2 → 10.2.23
tableau tableau_server · 10.3 → 10.3.23
tableau tableau_server · 10.4 → 10.4.19
tableau tableau_server · 10.5 → 10.5.18
tableau tableau_server · 2018.1 → 2018.1.15
tableau tableau_server · 2018.2 → 2018.12
tableau tableau_server · 2018.3 → 2018.3.9
tableau tableau_server · 2019.1 → 2019.1.6
tableau tableau_server · 2019.2 → 2019.2.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References