Tibco Hawk vulnerabilities

9 known vulnerabilities affecting tibco/hawk.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2024-3182MEDIUMCVSS 6.5≥ 6.2.0, < 6.2.42024-05-15
CVE-2024-3182 [MEDIUM] CWE-200 CVE-2024-3182: Install-type password disclosure vulnerability in Universal Installer including the Silent Installer Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.
cvelistv5nvd
CVE-2023-26219HIGHCVSS 8.8fixed in 6.2.32023-10-25
CVE-2023-26219 [HIGH] CWE-798 CVE-2023-26219: The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribut The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associ
nvd
CVE-2022-41564MEDIUMCVSS 6.5≥ 6.1.0, < 6.2.22023-02-14
CVE-2022-41564 [MEDIUM] CWE-522 CVE-2022-41564: The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Ha The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO Operational Intelligence Hawk Red
nvd
CVE-2022-29167HIGH≥ 0, < 9.0.12022-05-23
CVE-2022-29167 [HIGH] CWE-1333 Uncontrolled Resource Consumption in Hawk Uncontrolled Resource Consumption in Hawk Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic verification of the request and response, covering the HTTP method, request URI, host, and optionally the request payload. Hawk used a regular expression to parse `Host` HTTP header (`Hawk.utils.parseHost()`), which was subject to regular expression DoS attac
ghsaosv
CVE-2016-2515HIGH≥ 4.0.0, < 4.1.1≥ 0, < 3.1.32018-07-31
CVE-2016-2515 [HIGH] CWE-1333 Regular Expression Denial of Service in hawk Regular Expression Denial of Service in hawk Versions of `hawk` prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI's. ## Recommendation Update to hawk version 4.1.1 or later.
ghsaosv
CVE-2008-3338CRITICALCVSS 10.0≤ 4.8.0v4.6.0+2 more2008-08-13
CVE-2008-3338 [CRITICAL] CWE-119 CVE-2008-3338: Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkh Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1; Runtime Agent (TRA) before 5.6.0; iProcess Engine 10.3.0 through 10.6.2 and 11.0.0; and Mainframe Service Tracker before 1.1.0 might allow remote attackers to execute arbitrary code via a crafted message.
nvd
CVE-2008-1703CRITICALCVSS 9.3≤ 4.8.02008-04-11
CVE-2008-1703 [CRITICAL] CWE-119 CVE-2008-1703: Multiple buffer overflows in TIBCO Software Rendezvous before 8.1.0, as used in multiple TIBCO produ Multiple buffer overflows in TIBCO Software Rendezvous before 8.1.0, as used in multiple TIBCO products, allow remote attackers to execute arbitrary code via a crafted message.
nvd
CVE-2006-2830HIGHCVSS 7.5v4.6.12006-06-05
CVE-2006-2830 [HIGH] CVE-2006-2830: Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent (TRA) before 5.4, and Hawk bef Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent (TRA) before 5.4, and Hawk before 4.6.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the HTTP administrative interface.
nvd
CVE-2006-2829MEDIUMCVSS 6.8v4.6.02006-06-05
CVE-2006-2829 [MEDIUM] CVE-2006-2829: Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent ( Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma.
nvd