Description

TIBCO, a leading provider of enterprise integration and management software, has issued urgent security advisories for its Operational Intelligence Hawk platform. Two critical vulnerabilities, CVE-2024-10217 and CVE-2024-10218, have been discovered, posing significant security risks to users. Both flaws carry a CVSSv4 score of 9.2, indicating their high severity and potential impact on affected systems. The vulnerabilities affect TIBCO Hawk versions 6.2.0 through 6.3.0 and Operational Intelligence Hawk versions 7.2.0 through 7.2.2. CVE-2024-10217 is a Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into Hawk, potentially compromising user accounts and gaining unauthorized access to sensitive information. CVE-2024-10218 is a Stored XML External Entity (XEE) vulnerability that enables attackers to read sensitive files on the host system, including confidential data and configuration files. TIBCO has released updated versions to address these issues and urges users to upgrade immediately. Organizations using TIBCO Operational Intelligence Hawk should take immediate action to protect their systems and data. Although there are no reports of these vulnerabilities being actively exploited in the wild, their severity demands prompt attention. Users of affected versions should update to the recommended versions: TIBCO Hawk versions 6.2.0 to 6.2.4 should update to version 6.2.5 or later, while users of TIBCO Hawk version 6.3.0 should update to 6.3.1 or later, and TIBCO Operational Intelligence Hawk versions 7.2.0 to 7.2.2 should be updated to 7.3.0 or later.