Tableau Server Multiple SQL Injection Vulnerabilities
BID:65171
Info
Tableau Server Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 65171 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1204 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2014 12:00AM |
| Updated: | Feb 11 2014 07:17AM |
| Credit: | Tanya Secker and Christiaan Esterhuizen. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Tableau Server Unspecified SQL Injection Vulnerabilitiy
Tableau Server is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database
Tableau Server prior to 8.0.7 and 8.1.2 are vulnerable.
Tableau Server is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database
Tableau Server prior to 8.0.7 and 8.1.2 are vulnerable.
Exploit / POC
Tableau Server Multiple SQL Injection Vulnerabilities
The following example URI is available:
http://www.example.com/views?modified_after=2013-12-08T23%3A00%3A00.000Z'%20or%20user%20like%20'Zrails
The following example URI is available:
http://www.example.com/views?modified_after=2013-12-08T23%3A00%3A00.000Z'%20or%20user%20like%20'Zrails
Solution / Fix
Tableau Server Multiple SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Tableau Server Unspecified SQL Injection Vulnerabilitiy
References:
References: