CVE-2024-3182: TIBCO Hawk

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.

Affected products

  • TIBCO Hawk: from 6.2.0, before 6.2.4 (fixed in 6.2.4)

Published 2024-05-15. Last modified 2026-06-17.