Highest overall severity: Medium


Summary:

When users attempt to publish workbooks on Tableau Server, they will get a distinctive error message if they attempt to publish a workbook to a project that does not exist. When users attempt to publish to an existing project, they will get a different error message if they do not have permission to publish to that project.


Impact:

A malicious user with publishing access may run a dictionary-style attack with the save-workbook operation to discover project names on Tableau Server.

Products and Versions: Tableau Server | Tableau Desktop | Tableau Bridge | Tableau Prep | Tableau Reader | Tableau Mobile | Tableau Public Desktop
*Versions that are no longer supported are not tested and may be vulnerable.


Tableau Server

Severity: Medium
CVSS3 Score: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - 4.3 Medium
Product Specific Notes: None.

Vulnerable versions:


Resolved in versions:

  • Tableau Server on Linux 2019.1.10
  • Tableau Server on Linux 2019.2.6
  • Tableau Server on Linux 2019.3.2

  • Tableau Server on Windows 2019.1.10
  • Tableau Server on Windows 2019.2.6
  • Tableau Server on Windows 2019.3.2

 

Tableau Desktop (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Bridge (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Prep (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Reader (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Mobile (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.

 

Tableau Public Desktop (Back to top of page)

Severity: N/A
CVSS3 Score: N/A
Product Specific Notes: Not affected.