Attacker Value
Unknown
(1 user assessed)
Exploitability
Unknown
(1 user assessed)
User Interaction
None
Privileges Required
Low
Attack Vector
Network
1

CVE-2019-15637

Disclosure Date: August 26, 2019
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.

Add Assessment

1
Ratings
Technical Analysis

Researched or exploited by North Korean state-sponsored attackers according to a July 2024 bulletin from multiple U.S. government agencies (not on KEV, so maybe just researched?): https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a

CVSS V3 Severity and Metrics
Base Score:
8.1 High
Impact Score:
5.2
Exploitability Score:
2.8
Vector:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • tableau

Products

  • tableau desktop,
  • tableau public desktop,
  • tableau reader,
  • tableau server

Additional Info

Technical Analysis