PT-2022-15264 · Tableau · Tableau Server
Published
2022-10-17
·
Updated
2022-10-19
·
CVE-2022-22128
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tableau Server (affected versions not specified)
Description
A path traversal vulnerability was discovered in Tableau Server Administration Agent's internal file transfer service, which could allow remote code execution. Tableau only supports product versions for 24 months after release, and older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tableau Server