CVE-2023-26219
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
25/10/2023
Last modified:
02/11/2023
Description
The Hawk Console and Hawk Agent components of TIBCO Software Inc.&#39;s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.&#39;s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.<br />
<br />
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:tibco:hawk:*:*:*:*:*:*:*:* | 6.2.3 (excluding) | |
| cpe:2.3:a:tibco:hawk_distribution_for_tibco_silver_fabric:*:*:*:*:*:*:*:* | 6.2.3 (excluding) | |
| cpe:2.3:a:tibco:operational_intelligence_hawk_redtail:*:*:*:*:*:*:*:* | 7.2.2 (excluding) | |
| cpe:2.3:a:tibco:runtime_agent:*:*:*:*:*:*:*:* | 5.12.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



