CVE-2019-15637

Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
mitreCNA
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AC:L/AV:N/A:L/C:H/I:N/PR:L/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
tableautableau_server
10.5 ≤
𝑥
≤ 10.5.18
tableautableau_server
2018.1 ≤
𝑥
≤ 2018.1.15
tableautableau_server
2018.2 ≤
𝑥
≤ 2018.12
tableautableau_server
2018.3 ≤
𝑥
≤ 2018.3.9
tableautableau_server
2019.1 ≤
𝑥
≤ 2019.1.6
tableautableau_server
2019.2 ≤
𝑥
≤ 2019.2.2
tableautableau_server
10.2 ≤
𝑥
≤ 10.2.23
tableautableau_server
10.3 ≤
𝑥
≤ 10.3.23
tableautableau_server
10.4 ≤
𝑥
≤ 10.4.19
tableautableau_server
10.5 ≤
𝑥
≤ 10.5.18
tableautableau_server
2018.1 ≤
𝑥
≤ 2018.1.15
tableautableau_server
2018.2 ≤
𝑥
≤ 2018.12
tableautableau_server
2018.3 ≤
𝑥
≤ 2018.3.9
tableautableau_server
2019.1 ≤
𝑥
≤ 2019.1.6
tableautableau_server
2019.2 ≤
𝑥
≤ 2019.2.2
tableautableau_desktop
10.2 ≤
𝑥
≤ 10.2.23
tableautableau_desktop
10.3 ≤
𝑥
≤ 10.3.23
tableautableau_desktop
10.4 ≤
𝑥
≤ 10.4.19
tableautableau_desktop
10.5 ≤
𝑥
≤ 10.5.18
tableautableau_desktop
2018.1 ≤
𝑥
≤ 2018.1.15
tableautableau_desktop
2018.2 ≤
𝑥
≤ 2018.2.12
tableautableau_desktop
2018.3 ≤
𝑥
≤ 2018.3.9
tableautableau_desktop
2019.1 ≤
𝑥
≤ 2019.1.6
tableautableau_desktop
2019.2 ≤
𝑥
≤ 2019.2.2
tableautableau_desktop
10.2 ≤
𝑥
≤ 10.2.23
tableautableau_desktop
10.3 ≤
𝑥
≤ 10.3.23
tableautableau_desktop
10.4 ≤
𝑥
≤ 10.4.19
tableautableau_desktop
10.5 ≤
𝑥
≤ 10.5.18
tableautableau_desktop
2018.1 ≤
𝑥
≤ 2018.1.15
tableautableau_desktop
2018.2 ≤
𝑥
≤ 2018.2.12
tableautableau_desktop
2018.3 ≤
𝑥
≤ 2018.3.9
tableautableau_desktop
2019.1 ≤
𝑥
≤ 2019.1.6
tableautableau_desktop
2019.2 ≤
𝑥
≤ 2019.2.2
tableautableau_reader
10.2 ≤
𝑥
≤ 10.2.2
tableautableau_public_desktop
10.2 ≤
𝑥
≤ 10.2.2
𝑥
= Vulnerable software versions