CVE-2019-15637 EXPLOIT
8.1
HIGH · CVSS 3.1 · EPSS 14.3% (pctl 97)
Patch early
A public exploit exists.
Description
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 14.31% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-611 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-08-26 |
| Last modified | 2026-06-17 |
Affected (7)
| Vendor | Product |
|---|---|
| apple | macos |
| linux | linux kernel |
| microsoft | windows |
| tableau | tableau desktop |
| tableau | tableau public desktop |
| tableau | tableau reader |
| tableau | tableau server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Tableau - XML External Entity | 2019-08-27 |
References
- https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products
- https://github.com/minecrater/exploits/blob/master/TableauXXE.py
- https://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html
- https://community.tableau.com/community/security-bulletins/blog/2019/08/22/important-adv-2019-030-xxe-vulnerability-in-tableau-products
- https://github.com/minecrater/exploits/blob/master/TableauXXE.py
- https://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html
→ the Explorer · watch your stack · NVD