Salesforce Tableau Server
cpe:2.3:a:tableausoftware:tableau_server:*:*:*:*:*:*:*, +2 more
- < 2025.1.3
- < 2024.2.12
- < 2023.3.19
A type confusion vulnerability has been identified in Salesforce Tableau Server and Tableau Desktop on Windows and Linux. This vulnerability, present in versions prior to Tableau Server 2025.1.3, 2024.2.12, and 2023.3.19, allows local code inclusion by exploiting incompatible type handling. The issue arises within the File Upload modules of both Tableau Server and Tableau Desktop.
Exploitation of this vulnerability could lead to local code inclusion, allowing an attacker to execute arbitrary code on the affected system.
Users are advised to update Tableau Server and Tableau Desktop to the latest supported versions. Tableau Server updates can be downloaded from the Tableau Server Maintenance Release page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.