Server
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-1629 | Med | 0.40 | 6.1 | 0.01 | Mar 26, 2021 | Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users. | ||
| CVE-2025-52455 | Med | 0.34 | 5.3 | 0.00 | Jul 25, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | ||
| CVE-2014-1204 | 0.03 | — | 0.04 | Jan 31, 2014 | SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be exploited by unauthenticated remote attackers if the guest user is enabled. |
- risk 0.40cvss 6.1epss 0.01
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
- risk 0.34cvss 5.3epss 0.00
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
- CVE-2014-1204Jan 31, 2014risk 0.03cvss —epss 0.04
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be exploited by unauthenticated remote attackers if the guest user is enabled.
Page 2 of 2