Loading
ただいま大変多くのお問い合わせをいただいており、ご連絡までにお時間を頂戴しております続きを読む

Tableau Unaffected by Apache Log4j CVEs (CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34480)

公開日: Jul 8, 2026
説明
Vulnerability scanners may flag the following Apache Log4j JAR files bundled with Tableau Desktop, Tableau Prep Builder, and Tableau Bridge:

  • oauthservice.jar — located at C:\Program Files\Tableau\Tableau <version>\bin\
  • loom-rest-api-1.0-SNAPSHOT.jar
  • jdbcserver.jar

These JARs contain Log4j Core versions 2.17.2 or 2.24.3. Since customers cannot replace bundled JARs independently, scanners raise these as findings against the following CVEs:

CVE                         Title                                                CVSS           Log4j Versions Affected
CVE-2025-68161    Apache Log4j MitM Vulnerability  HIGH         ≤ 2.24.3
CVE-2026-34477    SSL Hostname Bypass                   HIGH          ≤ 2.25.3
CVE-2026-34478    RFC5424Layout Log Injection       MEDIUM     2.21.0–2.25.3
CVE-2026-34480    XmlLayout Invalid XML Output     HIGH          ≤ 2.25.3

CVE-2025-68161 – Apache Log4j MitM Vulnerability
This vulnerability allows man-in-the-middle (MitM) attacks by exploiting Log4j's SocketAppender or HttpAppender configurations to intercept communications. The scanner flags this based on the Log4j version range alone.

CVE-2026-34477 – SSL Hostname Bypass
This is an incomplete fix for CVE-2025-68161 — SSL hostname verification is only enforced when log4j2.sslVerifyHostName is explicitly enabled, leaving a bypass vector via SocketAppender/HttpAppender.

CVE-2026-34478 – RFC5424Layout Log Injection
Exploits the Rfc5424Layout configuration in Log4j's XML config, enabling CRLF log injection via undocumented renamed security-relevant attributes. The scanner triggers on any log4j-core 2.21.0–2.25.3 installation.

CVE-2026-34480 – XmlLayout Invalid XML Output
XmlLayout in Log4j Core (≤ 2.25.3) fails to sanitize XML 1.0-forbidden characters in log messages, producing invalid XML output that disrupts XML-based integrations.

Affected Products:
  • Tableau Desktop — all current versions
  • Tableau Prep Builder — all current versions
  • Tableau Bridge — all current versions
Note: Tableau Cloud (managed by Salesforce) and Tableau Server follow separate patch cycles and separate CVE assessments. This article covers on-premises client products only.
解決策
All four CVEs are assessed as Not Affected for Tableau Desktop, Tableau Prep Builder, and Tableau Bridge. 

CVE                        Tableau Assessment    Reason
CVE-2025-68161    ✅ Not Affected        Tableau does not configure SocketAppender or HttpAppender in any service or process. The vulnerable code path is not exercised.
CVE-2026-34477    ✅ Not Affected        Same root precondition as CVE-2025-68161 — SocketAppender/HttpAppender not in use. Not affected for the same reason.
CVE-2026-34478    ✅ Not Affected        Tableau does not configure Rfc5424Layout in any service or process in Desktop, Prep Builder, or Bridge. The exploit precondition is absent.
CVE-2026-34480    ✅ Not Affected        Tableau does not configure XmlLayout in any service. No log output passes through the affected code path.

These findings are scanner false positives based solely on Log4j version-range matching. The specific configurations required to make these vulnerabilities exploitable are not present in any standard Tableau deployment. No customer-side action or workaround is required.

Log4j 2.25.4 Upgrade Timeline (to fully eliminate scanner findings)

Product Line            Fix Release                                    Status
Tableau 2025.1.x    July 2026 Maintenance Release    Planned
Tableau 2025.3.x    July 2026 Maintenance Release    Planned
Tableau 2026.2       Released                                       — Log4j 2.25.4 inclusion pending confirmation in release notes    Check https://www.tableau.com/support/releases/desktop/2026.2

We recommend planning an upgrade once the July 2026 MRs are published to fully resolve scanner findings. 

For formal security or compliance documentation, submit a request to: https://security.salesforce.com/contact 

 

 

その他のリソース
ナレッジ記事番号

005388638

 
読み込み中
Salesforce Help | Article