Path Traversal Vulnerability in Salesforce Tableau Server on Windows and Linux
CVE-2025-52450

Currently unrated

Key Information:

Vendor

Salesforce

Vendor
CVE Published:
22 August 2025

What is CVE-2025-52450?

A vulnerability exists in Salesforce Tableau Server allowing for improper restriction of pathnames, leading to potential absolute path traversal attacks. This flaw particularly affects the 'create-data-source-from-file-upload' modules on both Windows and Linux platforms, making sensitive files accessible to unauthorized users. The issue is present in various versions of Tableau Server prior to the specified updates, creating significant risk for data exposure.

Affected Version(s)

Tableau Server Windows 0 < 2025.1.3

Tableau Server Windows 0 < 2024.2.12

Tableau Server Windows 0 < 2023.3.19

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52450 : Path Traversal Vulnerability in Salesforce Tableau Server on Windows and Linux