TIBCO Runtime Agent Security Advisory FAQ
Why are these advisories being issued?
Security vulnerabilities have been discovered in versions of TIBCO Rendezvous® 7.5.0 and earlier and in TIBCO Hawk® version 4.6.0 and earlier.
Which customers are affected?
TIBCO Runtime Agent includes parts of Hawk® and all of Rendezvous® as part of its install, so all customers using Runtime Agent™ earlier than version 5.4 are affected by these advisories.
How should customers handle this issue?
Affected customers with current TIBCO maintenance contracts should upgrade to Runtime Agent version 5.4 or later. The upgrade eliminates the Rendezvous and Hawk issues within Runtime Agent.
Do I need to upgrade all of the Runtime Agent components?
TIBCO strongly recommends a complete upgrade.
What if I cannot upgrade Runtime Agent at this time?
If you are not able to upgrade Runtime Agent at this time, steps can be taken to mitigate the vulnerabilities. Separate actions must be taken for Rendezvous and Hawk. For details on these actions, please see the Rendezvous Security Advisory FAQ and the Hawk Security Advisory FAQ .
What if I do not have a current maintenance contract?
The vulnerabilities can be mitigated without a software upgrade by taking the remedial steps detailed in the Rendezvous Security Advisory and the Hawk Security Advisory .
How will customers who receive TIBCO software via OEM partners be affected?
Customers of OEM partners can receive new versions of TIBCO products from their OEM partner. Please contact your OEM partner to upgrade.
What is TIBCO doing to prevent future security issues?
TIBCO takes security very seriously. We perform rigorous testing for every product release, as well as code audits, structured walkthroughs and peer reviews. TIBCO has identified security vulnerabilities in products during internal testing and reviews and corrected them prior to release. TIBCO constantly evaluates and augments its security measures and will continue to do so.
Where can I get more information?
If you have a current maintenance contract with TIBCO, you can log a service request with TIBCO Global Support and then call your support telephone number.
###
The information on this page is being provided to you on an "AS IS" and "AS-AVAILABLE" basis. The issues described on this page may or may not impact your system(s). TIBCO makes no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, WITHOUT LIMITATION, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT AND FITNESS FOR A PARTICULAR PURPOSE ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT TIBCO SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. The information on this page is being provided to you under the terms of your license and/or services agreement with TIBCO, and may be used only for the purposes contemplated by the agreement. If you do not have such an agreement with TIBCO, this information is provided under the TIBCO.com Terms of Use, and may be used only for the purposes contemplated by such Terms of Use.



