CVE-2019-15637 is an XML External Entity (XXE) vulnerability affecting multiple Tableau products, including Server, Desktop, Reader, and Public Desktop. This flaw allows an attacker to achieve information disclosure or denial of service by crafting malicious workbooks, extensions, or data sources. With a CVSS score of 8.1 (High), it has a low attack complexity and requires no user interaction, making it a significant risk. While not listed in CISA's KEV catalog, a public exploit (EDB-47308) exists, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.5, <= 10.5.18CPE matchmatch criteria | cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:* | ||
>= 2018.1, <= 2018.1.15CPE matchmatch criteria | cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:* | ||
>= 2018.2, <= 2018.12CPE matchmatch criteria | cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:* | ||
>= 2018.3, <= 2018.3.9CPE matchmatch criteria | cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:* | ||
>= 2019.1, <= 2019.1.6CPE matchmatch criteria | cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.