7.5
CVSSv2

CVE-2014-1204

Published: 31/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Tableau Server 8.0.x prior to 8.0.7 and 8.1.x prior to 8.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be exploited by unauthenticated remote attackers if the guest user is enabled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tableausoftware tableau server 8.0.2

tableausoftware tableau server 8.0.3

tableausoftware tableau server 8.0.6

tableausoftware tableau server 8.1

tableausoftware tableau server 8.0.4

tableausoftware tableau server 8.0.5

tableausoftware tableau server 8.0

tableausoftware tableau server 8.0.1

tableausoftware tableau server 8.1.1

Exploits

Trustwave's SpiderLabs Security Advisory TWSL2014-003: Blind SQL Injection Vulnerability in Tableau Server Published: 02/07/14 Version: 11 Vendor: Tableau Software (wwwtableausoftwarecom) Product: Tableau Server Versions affected: 81X before 812 and 80X before 807 Not present in 70X and earlier Product description: Tableau ...
Tableau server suffers from a remote blind SQL injection vulnerability Versions 81X before 812 and 80X before 807 are affected ...