Salesforce Tableau Server
cpe:2.3:a:tableau:server:*:*:*:*:*:*:*, +2 more
- < 2025.1.3
- < 2024.2.12
- < 2023.3.19
A vulnerability allowing authorization bypass through user-controlled keys has been identified in Salesforce Tableau Server. This issue affects versions prior to 2025.1.3, prior to 2024.2.12, and prior to 2023.3.19, on both Windows and Linux platforms, specifically within the tab-doc API modules. The vulnerability allows for interface manipulation, granting unauthorized access to the production database cluster.
Exploitation of this vulnerability could lead to unauthorized access and manipulation of data in the production database cluster.
Users are advised to update Tableau Server to the latest supported maintenance release for their branch. The update can be downloaded from the Tableau Server Maintenance Release page. Additionally, customers with a Trino (formerly Presto) driver installed should update their driver to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.