CVE-2023-26219

HIGH

TIBCO Hawk <6.2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.

References (1)

Core 1
Core References

Scores

CVSS v3 7.4
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (4)
tibco/hawk < 6.2.3
tibco/hawk_distribution_for_tibco_silver_fabric < 6.2.3
tibco/operational_intelligence_hawk_redtail < 7.2.2
tibco/runtime_agent < 5.12.3
Published Oct 25, 2023
Tracked Since Feb 18, 2026