Security Advisory Regarding TIBCO Operational Intelligence Hawk RedTail

Security Advisory Regarding TIBCO Operational Intelligence Hawk RedTail

book

Article ID: KB0070990

calendar_today

Updated On:

Products Versions
TIBCO Hawk 6.2.2 and below
TIBCO Hawk Distribution for TIBCO Silver Fabric 6.2.2 and below
TIBCO Runtime Agent (TRA) 5.12.2 and below

Description

TIBCO Operational Intelligence Hawk RedTail Credential Exposure Vulnerability

Original release date: October 24, 2023
Last revised: —
CVE-2023-26219
Source: TIBCO Software Inc.

Description

 

The components listed above contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers.

 

Impact

 

The impact of this vulnerability includes the theoretical possibility that an attacker could access the message stream of the EMS server, or in the worst case, gain administrative access to the server.

CVSS v3.1 Base Score: 7.4 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)

    Environment

    Products Affected - TIBCO Hawk 6.2.2 and below - TIBCO Operational Intelligence Hawk RedTail 7.2.1 and below - TIBCO Hawk Distribution for TIBCO Silver Fabric 6.2.2 and below - TIBCO Runtime Agent 5.12.2 and below The following components are affected: - Hawk Console - Hawk Agent

    Resolution

    TIBCO has released updated versions of the affected systems which address this issue:

    • TIBCO Hawk 6.2.2 and below: update to version 6.2.3 or later
    • TIBCO Operational Intelligence Hawk RedTail 7.2.1 and below: update to version 7.2.2 or later
    • TIBCO Hawk Distribution for TIBCO Silver Fabric 6.2.2 and below: update to version 6.2.3 or later
    • TIBCO Runtime Agent 5.12.2 and below: update to version 5.12.3 or later

    Issue/Introduction

    Security Advisory Regarding TIBCO Operational Intelligence Hawk RedTail Credential Exposure Vulnerability

    Additional Information

    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26219
    https://www.tibco.com/support/advisories/2023/10/tibco-security-advisory-october-24-2023-tibco-tibco-operational-intelligence-hawk-redtail-cve-0