PT-2022-15264 · Tableau · Tableau Server

Published

2022-10-17

·

Updated

2022-10-19

·

CVE-2022-22128

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tableau Server (affected versions not specified)
Description A path traversal vulnerability was discovered in Tableau Server Administration Agent's internal file transfer service, which could allow remote code execution. Tableau only supports product versions for 24 months after release, and older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-22128

Affected Products

Tableau Server