8.5
/ 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Basic Information
ID
CVE-2025-52449
Source
Salesforce
Published
Jul 25, 2025 at 18:56
Modified
Jul 25, 2025 at 19:54
Affected Product
Vendor
Salesforce
Product
Tableau Server
Affected Versions
Salesforce Tableau Server 0
Salesforce Tableau Server 0
Salesforce Tableau Server 0
Salesforce Tableau Server 0
Salesforce Tableau Server 0