PT-2023-20546 · Tibco Software · Tibco Runtime Agent+3

Publicado

2023-10-24

·

Atualizado

2023-11-02

·

CVE-2023-26219

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TIBCO Hawk versions 6.2.2 and below TIBCO Hawk Distribution for TIBCO Silver Fabric versions 6.2.2 and below TIBCO Operational Intelligence Hawk RedTail versions 7.2.1 and below TIBCO Runtime Agent versions 5.12.2 and below
Description The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s products contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers.
Recommendations For TIBCO Hawk versions 6.2.2 and below, update to a version above 6.2.2 to resolve the issue. For TIBCO Hawk Distribution for TIBCO Silver Fabric versions 6.2.2 and below, update to a version above 6.2.2 to resolve the issue. For TIBCO Operational Intelligence Hawk RedTail versions 7.2.1 and below, update to a version above 7.2.1 to resolve the issue. For TIBCO Runtime Agent versions 5.12.2 and below, update to a version above 5.12.2 to resolve the issue. As a temporary workaround, consider restricting access to the Hawk Console’s and Agent’s log to minimize the risk of exploitation.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26219

Produtos afetados

Tibco Hawk
Tibco Hawk Distribution For Tibco Silver Fabric
Tibco Operational Intelligence Hawk Redtail
Tibco Runtime Agent