Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Metrics
Affected Vendors & Products
References
History
Sat, 26 Jul 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Salesforce
Salesforce tableau Server |
|
Vendors & Products |
Salesforce
Salesforce tableau Server |
Fri, 25 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 25 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | |
Weaknesses | CWE-434 | |
References |
|

Status: PUBLISHED
Assigner: Salesforce
Published: 2025-07-25T18:56:25.554Z
Updated: 2025-07-25T19:54:46.699Z
Reserved: 2025-06-16T20:18:48.946Z
Link: CVE-2025-52449

Updated: 2025-07-25T19:54:36.240Z

Status : Awaiting Analysis
Published: 2025-07-25T19:15:40.743
Modified: 2025-07-29T14:14:55.157
Link: CVE-2025-52449

No data.