CVE-2019-15637: Tableau Desktop

High severity, CVSS 8.1. EPSS: 14.3% chance of exploitation in the next 30 days.

Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.

Affected products

  • Tableau Tableau Desktop: from 10.2, up to and including 10.2.23; from 10.3, up to and including 10.3.23; from 10.4, up to and including 10.4.19; from 10.5, up to and including 10.5.18; from 2018.1, up to and including 2018.1.15; from 2018.2, up to and including 2018.2.12; …
  • Tableau Tableau Public Desktop: from 10.2, up to and including 10.2.2
  • Tableau Tableau Reader: from 10.2, up to and including 10.2.2
  • Tableau Tableau Server: from 10.5, up to and including 10.5.18; from 2018.1, up to and including 2018.1.15; from 2018.2, up to and including 2018.12; from 2018.3, up to and including 2018.3.9; from 2019.1, up to and including 2019.1.6; from 2019.2, up to and including 2019.2.2; …

Published 2019-08-26. Last modified 2026-06-17.