Path Traversal Vulnerability in Salesforce Tableau Server on Windows and Linux
CVE-2025-52450

6.5MEDIUM

Key Information:

Vendor

Salesforce

Vendor
CVE Published:
22 August 2025

What is CVE-2025-52450?

A vulnerability exists in Salesforce Tableau Server allowing for improper restriction of pathnames, leading to potential absolute path traversal attacks. This flaw particularly affects the 'create-data-source-from-file-upload' modules on both Windows and Linux platforms, making sensitive files accessible to unauthorized users. The issue is present in various versions of Tableau Server prior to the specified updates, creating significant risk for data exposure.

Affected Version(s)

Tableau Server Windows 0 < 2025.1.3

Tableau Server Windows 0 < 2024.2.12

Tableau Server Windows 0 < 2023.3.19

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.