Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22741 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. |
Fri, 31 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows Tableau Tableau tableau Server |
|
| CPEs | cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows Tableau Tableau tableau Server |
Sat, 26 Jul 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salesforce
Salesforce tableau Server |
|
| Vendors & Products |
Salesforce
Salesforce tableau Server |
Fri, 25 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Jul 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 25 Jul 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | |
| Weaknesses | CWE-639 | |
| References |
|
Status: PUBLISHED
Assigner: Salesforce
Published:
Updated: 2025-07-25T19:12:16.762Z
Reserved: 2025-06-16T20:18:48.946Z
Link: CVE-2025-52448
Updated: 2025-07-25T19:12:04.216Z
Status : Analyzed
Published: 2025-07-25T19:15:40.570
Modified: 2025-10-31T19:24:00.127
Link: CVE-2025-52448
No data.
OpenCVE Enrichment
Updated: 2025-07-26T11:55:05Z
EUVD