Security vulnerabilities have been discovered in versions of TIBCO Rendezvous® 7.5.0 and earlier.
The vulnerability potentially affects any customer running Rendezvous® 7.5.0 or earlier. This includes customers who have installed Rendezvous directly, as well as those who have installed it as part of TIBCO Hawk® or TIBCO Runtime Agent™.
The following Rendezvous daemons are affected: RVSD, RVRD, RVSRD, RVCACHE and RVA.
No.
The vulnerability could allow an attacker to execute arbitrary code on an affected system.
Affected customers with current maintenance agreements should upgrade to the latest version of Rendezvous (v7.5.1 or later), available from your TIBCO download site.
TIBCO strongly recommends that all instances of these daemons be replaced.
No.
If you are not able to upgrade the Rendezvous daemons at this time, actions can be taken to mitigate the vulnerability. For details on these actions, please see the Rendezvous Security Advisory.
No, Enterprise Messaging Service™ is not affected.
TIBCO Hawk and TIBCO Runtime Agent each bundles Rendezvous as part of the install process. When purchasing Hawk® or a TIBCO product that includes Runtime Agent® (e.g., TIBCO BusinessWorks™), customers typically only utilize the unaffected RVD within these packages. Customers who have purchased additional Rendezvous licenses that provide access to the affected daemons should upgrade their Rendezvous installation.
You do not need to upgrade Runtime Agent. An updated version of Rendezvous may be layered on an existing deployment without installing a new version of Runtime Agent. If Hawk is installed, stand-alone or as part of Runtime Agent, you should install a new version of Hawk.
The vulnerability can be mitigated without a software upgrade by taking the remedial configuration actions detailed.
Customers of OEM partners can receive new versions of TIBCO Hawk from their OEM partner. Please contact your OEM partner to upgrade.
TIBCO takes security very seriously. We perform rigorous testing for every product release, as well as code audits, structured walkthroughs and peer reviews. TIBCO has identified security vulnerabilities in products during internal testing and reviews and corrected them prior to release. TIBCO constantly evaluates and augments its security measures and will continue to do so.
If you have a current maintenance contract with TIBCO, you can log a service request with TIBCO Global Support and then call your support telephone number.
---------------------
The information on this page is being provided to you on an "AS IS" and "AS-AVAILABLE" basis. The issues described on this page may or may not impact your system(s). TIBCO makes no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, WITHOUT LIMITATION, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT AND FITNESS FOR A PARTICULAR PURPOSE ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT TIBCO SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. The information on this page is being provided to you under the terms of your license and/or services agreement with TIBCO, and may be used only for the purposes contemplated by the agreement. If you do not have such an agreement with TIBCO, this information is provided under the TIBCO.com Terms of Use, and may be used only for the purposes contemplated by such Terms of Use.
Discover the people, philosophy, and practices behind TIBCO
Find helpful links, documentation, and tech support
Collaborate and share knowledge with other TIBCO users
Stay up to speed on what’s new with TIBCO
Browse our comprehensive resource library
Read the latest trends, ideas, and product news from TIBCO
Don’t miss out on upcoming conferences, webinars, and more
Explore think-pieces geared towards executive leaders
Pursue your passion in an award-winning workplace
Up-to-date security release information
Get in touch with us and learn more about TIBCO
A global leader in enterprise data, TIBCO empowers its customers to connect, unify, and confidently predict business outcomes, solving the world’s most complex data-driven challenges.