Wiiisdom for Tableau Desktop - Third-party vulnerabilities (CVE) status

Wiiisdom for Tableau Desktop - Third-party vulnerabilities (CVE) status

Overview

This article lists the vulnerabilities (CVEs) reported on third-party libraries and components used by Wiiisdom for Tableau Desktop (Designer and CLI), whether the product is affected, and the remediation when needed. The list is sorted from the most recent CVE to the oldest.

Info
We recommend always using the latest Wiiisdom for Tableau version: third-party dependencies (Java runtime, Electron, Log4j, JDBC drivers, etc.) are updated in every release.

Legend

  • Not affected: the vulnerable code or feature is not used, not reachable or not configured in the product.
  • Low risk: the bundled component is in the affected range, but exploitation requires a non-default configuration or local access. It has been (or will be) upgraded anyway.
  • Affected – fixed: the product shipped an affected version of the component. The fixed product version is given in the details.
  • Not applicable: the component is not part of the product (for example, it belongs to a third-party platform installed on the same server).

Reported CVEs

CVEComponentImpactDetails & remediation
2026
CVE-2026-49844Apache Log4jNot affectedThe vulnerable code (JSON rendering of MapMessage) is not used by Wiiisdom for Tableau.
2025
CVE-2025-68161Apache Log4j 2.23.1 (kinesis-cli/kinesis.jar)Not affectedOnly affects the SocketAppender, a Log4j feature that Wiiisdom for Tableau does not use. Reported on versions 2025.2.1 and 2025.3.
2021
CVE-2021-44228Apache Log4j 2 (Log4Shell)Affected – fixedThe CLI, the Designer and the Performance Testing add-on (TabJolt) of versions older than 2021.4.1 embedded an affected Log4j version. Fixed in hotfix 2021.4.1 (December 2021). Upgrade to the latest version, especially if you use Performance Testing.

Other security updates

  • 2025.2: bundled Java runtime upgraded from Java 11 to Java 21.
  • 2023.3: json5 library updated (Designer).
  • 2023.2: bundled PostgreSQL JDBC driver updated.
  • 2023.1.1: Electron and Designer dependencies updated.
  • November 2025 – Shai-Hulud 2.0 npm supply-chain attack: not affected. No compromised package was found in Wiiisdom repositories.

Your CVE is not listed?

This page lists the vulnerabilities that were reported to us or analysed by our teams. It is not an exhaustive list of every CVE fixed by a component upgrade: check the Security section of the release notes for the complete list.

If your security scanner reports a CVE that is not listed here, open a ticket with the Support team and include the CVE ID, the product version, and the exact file or path flagged by the scanner. We will analyse it and add it to this page.