CVE-2022-22128
Last modified
CVE-2022-22128 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tableau | Tableau Server | >= 2020.4, <= 2020.4.20 |
| Tableau | Tableau Server | >= 2021.1, <= 2021.1.17 |
| Tableau | Tableau Server | >= 2021.2, <= 2021.2.15 |
| Tableau | Tableau Server | >= 2021.3, <= 2021.3.14 |
| Tableau | Tableau Server | >= 2021.4, <= 2021.4.9 |
| Tableau | Tableau Server | >= 2022.1, <= 2022.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22128?
How severe is CVE-2022-22128?
How do I fix CVE-2022-22128?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22122Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-22123In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable …5.4
- CVE-2022-22124In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable …5.4
- CVE-2022-22125In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable …4.8
- CVE-2022-22126Openmct versions 1.3.0 to 1.7.7 are vulnerable against store…6.1
- CVE-2022-22127Tableau is aware of a broken access control vulnerability pr…7.2
- CVE-2022-2213A vulnerability was found in SourceCodester Library Manageme…5.4
- CVE-2022-22137A memory corruption vulnerability exists in the ioca_mys_rgb…6.5
- CVE-2022-22138All versions of package fast-string-search are vulnerable to…7.5
- CVE-2022-22139Uncontrolled search path in the Intel(R) XTU software before…7.3
- CVE-2022-2214A vulnerability was found in SourceCodester Library Manageme…8.8
- CVE-2022-22140An os command injection vulnerability exists in the confsrv …9.8
Are you affected by CVE-2022-22128?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
