Highest overall severity: High

 

Summary:

Tableau Server uses the Java JRE. The April 2019 update to the Java JRE contained an unspecified High severity issue (CVE-2019-2699) that might present a risk to Tableau Server. We have upgraded to the July 2019 release of the JRE that contains fixes for other CVEs as well.
The following CVEs have been addressed:

 

Impact:

From https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs.

 

Products and Versions: Tableau Server | Tableau Desktop | Tableau Bridge | Tableau Prep | Tableau Reader | Tableau Mobile | Tableau Public Desktop
*Versions that are no longer supported are not tested and may be vulnerable.

 

Tableau Server

Severity: High
CVSS3 Score: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - 8.1 High

Vulnerable versions:

  • Tableau Server on Linux 10.5 through 10.5.19
  • Tableau Server on Linux 2018.1 through 2018.1.16
  • Tableau Server on Linux 2018.2 through 2018.2.13
  • Tableau Server on Linux 2018.3 through 2018.3.10
  • Tableau Server on Linux 2019.1 through 2019.1.7
  • Tableau Server on Linux 2019.2 through 2019.2.3
  • Tableau Server on Linux 2019.3

  • Tableau Server on Windows 10.3 through 10.3.24
  • Tableau Server on Windows 10.4 through 10.4.20
  • Tableau Server on Windows 10.5 through 10.5.19
  • Tableau Server on Windows 2018.1 through 2018.1.16
  • Tableau Server on Windows 2018.2 through 2018.2.13
  • Tableau Server on Windows 2018.3 through 2018.3.10
  • Tableau Server on Windows 2019.1 through 2019.1.7
  • Tableau Server on Windows 2019.2 through 2019.2.3
  • Tableau Server on Windows 2019.3

 

Resolved in versions:

  • Tableau Server on Linux 10.5.20
  • Tableau Server on Linux 2018.1.17
  • Tableau Server on Linux 2018.2.14
  • Tableau Server on Linux 2018.3.11
  • Tableau Server on Linux 2019.1.8
  • Tableau Server on Linux 2019.2.4
  • Tableau Server on Linux 2019.3.1

  • Tableau Server on Windows 10.3.25
  • Tableau Server on Windows 10.4.21
  • Tableau Server on Windows 10.5.20
  • Tableau Server on Windows 2018.1.17
  • Tableau Server on Windows 2018.2.14
  • Tableau Server on Windows 2018.3.11
  • Tableau Server on Windows 2019.1.8
  • Tableau Server on Windows 2019.2.4
  • Tableau Server on Windows 2019.3.1

 

Tableau Desktop (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Bridge (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Prep (Back to top of page)

Severity: Medium
CVSS3 Score: AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H - 6.4 Medium

Vulnerable versions:

  • Tableau Prep on Mac 2018.1.1 through 2019.3.1

  • Tableau Prep on Windows 2018.1.1 through 2019.3.1

 

Resolved in versions:

  • Tableau Prep on Mac 2019.3.2

  • Tableau Prep on Windows 2019.3.2

 

Tableau Reader (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Mobile (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Public Desktop (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.