PT-2023-20546 · Tibco Software · Tibco Runtime Agent+3
Publicado
2023-10-24
·
Atualizado
2023-11-02
·
CVE-2023-26219
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIBCO Hawk versions 6.2.2 and below
TIBCO Hawk Distribution for TIBCO Silver Fabric versions 6.2.2 and below
TIBCO Operational Intelligence Hawk RedTail versions 7.2.1 and below
TIBCO Runtime Agent versions 5.12.2 and below
Description
The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s products contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers.
Recommendations
For TIBCO Hawk versions 6.2.2 and below, update to a version above 6.2.2 to resolve the issue.
For TIBCO Hawk Distribution for TIBCO Silver Fabric versions 6.2.2 and below, update to a version above 6.2.2 to resolve the issue.
For TIBCO Operational Intelligence Hawk RedTail versions 7.2.1 and below, update to a version above 7.2.1 to resolve the issue.
For TIBCO Runtime Agent versions 5.12.2 and below, update to a version above 5.12.2 to resolve the issue.
As a temporary workaround, consider restricting access to the Hawk Console’s and Agent’s log to minimize the risk of exploitation.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tibco Hawk
Tibco Hawk Distribution For Tibco Silver Fabric
Tibco Operational Intelligence Hawk Redtail
Tibco Runtime Agent