### [CVE-2024-3182](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3182) ![](https://img.shields.io/static/v1?label=Product&message=Hawk&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=6.2.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=blue) ### Description Install-type password disclosure vulnerability inĀ Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files. ### POC #### Reference - https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213/ #### Github No PoCs found on GitHub currently.