Skip to main content

We've recently become aware of exploits of the ZK Java Framework, as noted in CVE-2022-36537 - CVE - CVE-2022-36537 (mitre.org). I've not been able to find anything on Tableau's site about this and it is unclear if Tableau uses the ZK Java Framework in any of it's products.

I would like to know if this has any impact on any of the Tableau products?

Thanks.

1 answer
  1. Mar 7, 2023, 1:58 PM

    Hi there Warren,

     

    I've held off on answering this query as I was awaiting the official response from the Security Team. Tableau does not use the ZK Java Framework, therefore it is not affected.

     

    Please see the official response from the team below:

    "Due to the nature of our services, Salesforce may not comment or provide information to individual inquiries on potential vulnerabilities to the services. If a potential vulnerability has substantial impact on the services and requires a public statement, then this will be published in the security advisory section of the trust website: https://security.salesforce.com/security-advisoriesThe Salesforce incident response team monitors a wide range of public and private threat intelligence feeds and communities. This threat intelligence is processed in near-real time and leveraged in the following ways to detect and respond to threats:

    • Detection: Relevant IOCs (indicators of compromise) are automatically distributed as new detection signatures to our security monitoring infrastructure.
    • Hunting: Relevant IOCs are used to sweep our environment (and historical log data) for any suspicious artefacts or activity.
    • Situational Awareness: Relevant threat intelligence is summarized and communicated to all members of the CSIRT.

    When reported by vendors, vulnerabilities are entered into the salesforce central ticketing system and are assigned an internal vulnerability ranking according on the OWASP risk rating framework based on likelihood and impact (CVE). These issues are tracked through to resolution in accordance with company policy and industry best practice recommendations. The effectiveness of this process and its implementation has been assessed by a third party auditor as part of our SOC 2 audit performed every 6 months. Please refer “SOC 2 Report - Corporate Services” available from the Salesforce Security & Compliance Documentation Portal: https://compliance.salesforce.com/en/soc-2"

0/9000