Salesforce Tableau Server
cpe:2.3:a:tableau:server:*:*:*:*:*:*:*, +2 more
- < 2025.1.3
- < 2024.2.12
- < 2023.3.19
A path traversal vulnerability allowing absolute path traversal has been identified in Salesforce Tableau Server. This issue affects versions prior to 2025.1.3, prior to 2024.2.12, and prior to 2023.3.19, on both Windows and Linux platforms, specifically within the tabdoc API's duplicate-data-source modules.
Exploitation of this vulnerability allows for absolute path traversal, potentially leading to unauthorized access to files and directories on the server.
Users are advised to update Tableau Server to the latest supported maintenance release for their branch. The latest version can be downloaded from the Tableau Server Maintenance Release page. Additionally, customers with a Trino driver installed should update to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.