Tibco Hawk vulnerabilities
9 known vulnerabilities affecting tibco/hawk.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-3182MEDIUMCVSS 6.5≥ 6.2.0, < 6.2.42024-05-15
CVE-2024-3182 [MEDIUM] CWE-200 CVE-2024-3182: Install-type password disclosure vulnerability in Universal Installer including the Silent Installer
Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.
cvelistv5nvd
CVE-2023-26219HIGHCVSS 8.8fixed in 6.2.32023-10-25
CVE-2023-26219 [HIGH] CWE-798 CVE-2023-26219: The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribut
The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associ
nvd
CVE-2022-41564MEDIUMCVSS 6.5≥ 6.1.0, < 6.2.22023-02-14
CVE-2022-41564 [MEDIUM] CWE-522 CVE-2022-41564: The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Ha
The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO Operational Intelligence Hawk Red
nvd
CVE-2022-29167HIGH≥ 0, < 9.0.12022-05-23
CVE-2022-29167 [HIGH] CWE-1333 Uncontrolled Resource Consumption in Hawk
Uncontrolled Resource Consumption in Hawk
Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic verification of the request and response, covering the HTTP method, request URI, host, and optionally the request payload. Hawk used a regular expression to parse `Host` HTTP header (`Hawk.utils.parseHost()`), which was subject to regular expression DoS attac
ghsaosv
CVE-2016-2515HIGH≥ 4.0.0, < 4.1.1≥ 0, < 3.1.32018-07-31
CVE-2016-2515 [HIGH] CWE-1333 Regular Expression Denial of Service in hawk
Regular Expression Denial of Service in hawk
Versions of `hawk` prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI's.
## Recommendation
Update to hawk version 4.1.1 or later.
ghsaosv
CVE-2008-3338CRITICALCVSS 10.0≤ 4.8.0v4.6.0+2 more2008-08-13
CVE-2008-3338 [CRITICAL] CWE-119 CVE-2008-3338: Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkh
Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1; Runtime Agent (TRA) before 5.6.0; iProcess Engine 10.3.0 through 10.6.2 and 11.0.0; and Mainframe Service Tracker before 1.1.0 might allow remote attackers to execute arbitrary code via a crafted message.
nvd
CVE-2008-1703CRITICALCVSS 9.3≤ 4.8.02008-04-11
CVE-2008-1703 [CRITICAL] CWE-119 CVE-2008-1703: Multiple buffer overflows in TIBCO Software Rendezvous before 8.1.0, as used in multiple TIBCO produ
Multiple buffer overflows in TIBCO Software Rendezvous before 8.1.0, as used in multiple TIBCO products, allow remote attackers to execute arbitrary code via a crafted message.
nvd
CVE-2006-2830HIGHCVSS 7.5v4.6.12006-06-05
CVE-2006-2830 [HIGH] CVE-2006-2830: Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent (TRA) before 5.4, and Hawk bef
Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent (TRA) before 5.4, and Hawk before 4.6.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the HTTP administrative interface.
nvd
CVE-2006-2829MEDIUMCVSS 6.8v4.6.02006-06-05
CVE-2006-2829 [MEDIUM] CVE-2006-2829: Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (
Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma.
nvd