oauthservice.jar — located at C:\Program Files\Tableau\Tableau <version>\bin\loom-rest-api-1.0-SNAPSHOT.jarjdbcserver.jarSocketAppender or HttpAppender configurations to intercept communications. The scanner flags this based on the Log4j version range alone.log4j2.sslVerifyHostName is explicitly enabled, leaving a bypass vector via SocketAppender/HttpAppender.Rfc5424Layout configuration in Log4j's XML config, enabling CRLF log injection via undocumented renamed security-relevant attributes. The scanner triggers on any log4j-core 2.21.0–2.25.3 installation.XmlLayout in Log4j Core (≤ 2.25.3) fails to sanitize XML 1.0-forbidden characters in log messages, producing invalid XML output that disrupts XML-based integrations.Note: Tableau Cloud (managed by Salesforce) and Tableau Server follow separate patch cycles and separate CVE assessments. This article covers on-premises client products only.
These findings are scanner false positives based solely on Log4j version-range matching. The specific configurations required to make these vulnerabilities exploitable are not present in any standard Tableau deployment. No customer-side action or workaround is required.
Log4j 2.25.4 Upgrade Timeline (to fully eliminate scanner findings):
Product Line Fix Release Status
Tableau 2025.1.x July 2026 Maintenance Release Planned
Tableau 2025.3.x July 2026 Maintenance Release Planned
Tableau 2026.2 Released — Log4j 2.25.4 inclusion pending confirmation in release notes Check https://www.tableau.com/support/releases/desktop/2026.2
We recommend planning an upgrade once the July 2026 MRs are published to fully resolve scanner findings.
For formal security or compliance documentation, submit a request to: https://security.salesforce.com/contact
005388638

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.