Impact
HCL IntelliOps Event Management contains a least‑privilege violation that permits an attacker who already holds some level of access to elevate privileges and reach resources that should otherwise be inaccessible. This flaw is categorized as CWE‑272.
Affected Systems
HCL IntelliOps Event Management, developed by HCL Software, lacks specified version information, so all releases are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate risk. The EPSS score is not supplied, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, suggesting no public evidence of exploitation yet. The exact attack vector is not indicated in the advisory, so it may be remote or local, but this is inferred.
OpenCVE Enrichment