Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-22127

Опубликовано: 25 мая 2022
Источник: nvd
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity Store for managing users. The vulnerability allows a malicious site administrator to change passwords for users in different sites hosted on the same Tableau Server, resulting in the potential for unauthorized access to data.Tableau Server versions affected are:2020.4.16, 2021.1.13, 2021.2.10, 2021.3.9, 2021.4.4 and earlierNote: All future releases of Tableau Server will address this security issue. Versions that are no longer supported are not tested and may be vulnerable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
Версия от 2020.4 (включая) до 2020.4.16 (включая)
cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
Версия от 2021.1 (включая) до 2021.1.13 (включая)
cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
Версия от 2021.2 (включая) до 2021.2.10 (включая)
cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
Версия от 2021.3 (включая) до 2021.3.9 (включая)
cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
Версия от 2021.4 (включая) до 2021.4.4 (включая)

EPSS

Процентиль: 59%
0.0039
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity Store for managing users. The vulnerability allows a malicious site administrator to change passwords for users in different sites hosted on the same Tableau Server, resulting in the potential for unauthorized access to data.Tableau Server versions affected are:2020.4.16, 2021.1.13, 2021.2.10, 2021.3.9, 2021.4.4 and earlierNote: All future releases of Tableau Server will address this security issue. Versions that are no longer supported are not tested and may be vulnerable.

EPSS

Процентиль: 59%
0.0039
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other