Learn about CVE-2020-6939 affecting Tableau Server versions 2018.2 through 2020.3. Discover the impact, technical details, and mitigation steps to prevent unauthorized access and account takeover.
Tableau Server installations configured with Site-Specific SAML are vulnerable to account takeover due to incorrect access control. Learn about the impact, technical details, and mitigation steps.
Understanding CVE-2020-6939
Tableau Server versions 2018.2 through 2020.3 are affected by an access control vulnerability that could lead to account compromise.
What is CVE-2020-6939?
Tableau Server instances with Site-Specific SAML allowing unauthenticated API access are at risk. Exploiting this flaw could enable unauthorized users to manipulate SAML settings, potentially resulting in account hijacking.
The Impact of CVE-2020-6939
Technical Details of CVE-2020-6939
Tableau Server's vulnerability stems from incorrect access control implementation.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Implement immediate and long-term security measures to safeguard against CVE-2020-6939.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates