Information disclosure in Tableau Server - #VU7303
Published: July 4, 2017
Tableau Server
Detailed vulnerability description
The disclosed vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper permission controls. A local attacker with access to Tableau logs can obtain passwords to data sources or secrets used to encrypt private keys used in SSL/TLS communication.
Successful exploitation of the vulnerability results in information disclosure.