CVE-2014-1204

SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be exploited by unauthenticated remote attackers if the guest user is enabled.

Date published : 2014-01-31

http://www.securityfocus.com/bid/65171

http://www.tableausoftware.com/support/releases/8.0.7