High severity8.1NVD Advisory· Published Aug 26, 2019· Updated Jun 17, 2026
CVE-2019-15637
CVE-2019-15637
Description
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:tableau:tableau_desktop:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:tableau:tableau_desktop:*:*:*:*:*:*:*:*range: >=10.2,<=10.2.23
- (no CPE)
cpe:2.3:a:tableau:tableau_public_desktop:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:tableau:tableau_public_desktop:*:*:*:*:*:*:*:*range: >=10.2,<=10.2.2
- (no CPE)
cpe:2.3:a:tableau:tableau_reader:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:tableau:tableau_reader:*:*:*:*:*:*:*:*range: >=10.2,<=10.2.2
- (no CPE)
cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*range: >=10.5,<=10.5.18
- (no CPE)
- Tableau/Server, Desktop, Reader, and Public Desktopdescription
Patches
Vulnerability mechanics
References
3- github.com/minecrater/exploits/blob/master/TableauXXE.pynvdExploitThird Party Advisory
- packetstormsecurity.com/files/154232/Tableau-XML-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-productsnvdVendor Advisory
News mentions
0No linked articles in our index yet.