← Voltar para CVEs
CVE-2022-22128
CRITICAL9.8
Descricao
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado10/17/2022
Ultima modificacao5/13/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
tableau:tableau_server
Fraquezas (CWE)
CWE-22CWE-22
Referencias
https://help.salesforce.com/s/articleView?id=000367027&type=1(security@salesforce.com)
https://kb.tableau.com/articles/Issue/issue-affecting-tableau-server-administration-agent(nvd@nist.gov)
https://help.salesforce.com/s/articleView?id=000367027&type=1(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.