TIBCO Operational Intelligence Hawk RedTail Credential Exposure Vulnerability
CVE-2023-26219

7.4HIGH

Summary

The Hawk Console and Hawk Agent components from TIBCO Software Inc. contain a vulnerability that may allow an attacker to exploit accessed logs to uncover credentials. This security issue affects several TIBCO products, particularly versions prior to 6.2.2 for TIBCO Hawk and TIBCO Hawk Distribution for TIBCO Silver Fabric, versions below 7.2.1 for TIBCO Operational Intelligence Hawk RedTail, and below 5.12.2 for TIBCO Runtime Agent. Organizations utilizing these affected versions should take immediate action to mitigate risks associated with potential credential exposure.

Affected Version(s)

TIBCO Hawk 0 <= 6.2.2

TIBCO Hawk Distribution for TIBCO Silver Fabric 0 <= 6.2.2

TIBCO Operational Intelligence Hawk RedTail 0 <= 7.2.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.