
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was identified in Tableau Server installations configured with Site-Specific SAML (CVE-2020-6939). The vulnerability affects both Windows and Linux versions of Tableau Server across multiple versions including 2018.2 through 2018.2.27, 2018.3 through 2018.3.24, 2019.1 through 2019.1.22, 2019.2 through 2019.2.18, 2019.3 through 2019.3.14, 2019.4 through 2019.4.13, 2020.1 through 2020.1.10, 2020.2 through 2020.2.7, and 2020.3 through 2020.3.2 (CVE Details).
The vulnerability allows the APIs to be used by unauthenticated users in Tableau Server installations that are configured with Site-Specific SAML. This security flaw enables unauthorized access to critical authentication configurations (NVD Database).
If successfully exploited, this vulnerability could allow a malicious user to configure Site-Specific SAML settings, potentially leading to account takeover for users of that site (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."