#VU103899 Path traversal in Tableau Server Administration Agent - CVE-2022-22128

 

#VU103899 Path traversal in Tableau Server Administration Agent - CVE-2022-22128

Published: February 12, 2025


Vulnerability identifier: #VU103899
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-22128
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Tableau Server Administration Agent
Software vendor:
Tableau

Description

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences within internal file transfer service. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system, leading to arbitrary code execution.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links