PT-2025-6208 · Tableau+1 · Tableau Server+1
Published
2025-02-11
·
Updated
2025-02-11
·
CVE-2025-26490
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Opcenter Intelligence versions prior to V2501
Description:
A personal access token disclosure vulnerability has been identified in Opcenter Intelligence, which is related to Tableau Server. This issue allows for the disclosure of personal access tokens. For more information, users can visit help.salesforce.com and search for the knowledge article with id 000390611.
Recommendations:
For Opcenter Intelligence versions prior to V2501, update to version V2501 or later to resolve the issue. As a temporary workaround, consider restricting access to Tableau Server to minimize the risk of exploitation. Additionally, users should avoid using personal access tokens in Tableau Server until the issue is resolved.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opcenter Intelligence
Tableau Server