CVE-2024-3182: Infoleak
Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3182?
CVE-2024-3182 is classified as a medium severity vulnerability due to the potential exposure of sensitive configuration information.
How do I fix CVE-2024-3182?
To mitigate CVE-2024-3182, update TIBCO Hawk to a secure version higher than 6.2.3 and review configuration files for exposed sensitive information.
What versions of TIBCO Hawk are affected by CVE-2024-3182?
CVE-2024-3182 affects TIBCO Hawk versions 6.2.0 to 6.2.3 inclusive.
What is the impact of CVE-2024-3182 on TIBCO's EMS password?
CVE-2024-3182 allows the user's EMS password to be disclosed, increasing the risk of unauthorized access.
Is there a workaround for CVE-2024-3182 if I cannot update TIBCO Hawk immediately?
A possible workaround for CVE-2024-3182 includes hardening access controls on configuration files to limit exposure until an update can be applied.