CVE-2024-3182

MEDIUM

TIBCO Hawk <6.2.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-200
Status published
Products (1)
TIBCO/Hawk 6.2.0 - 6.2.4
Published May 15, 2024
Tracked Since Feb 18, 2026