Description
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
Published: 2026-08-20
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL IntelliOps Event Management (IEM) contains a race condition that creates a timing window during which an attacker can alter a resource. Triggering this flaw can lead to unpredictable application behavior, potentially corrupting data or disrupting service availability.

Affected Systems

The vulnerability affects HCL Software’s IntelliOps Event Management (IEM). No specific product versions are listed, so all deployments of IEM are considered potentially impacted.

Risk and Exploitability

The CVSS score of 5.9 denotes moderate severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation. The description does not specify the required access level, so it is inferred that the attacker would need sufficient privilege within the IEM environment to exploit the race condition, likely via concurrent operations or submission of conflicting resource requests.

Generated by OpenCVE AI on August 20, 2026 at 22:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check HCL’s support or vendor portal for an official security patch or update for IEM.
  • Install the latest patch or upgrade to the most recent version of IEM once available.
  • If a patch is not yet available, review IEM configuration to reduce concurrent access to the affected resource or enable additional locking mechanisms to eliminate the timing window.
  • Monitor IEM logs for signs of unexpected resource modifications or inconsistent state changes after the timing window.

Generated by OpenCVE AI on August 20, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcl Software
Hcl Software iem
Vendors & Products Hcl Software
Hcl Software iem

Thu, 20 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
Title HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
Weaknesses CWE-362
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Hcl Software Iem
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-27T16:06:25.852Z

Reserved: 2025-10-10T09:04:02.283Z

Link: CVE-2025-62300

cve-icon Vulnrichment

Updated: 2026-08-27T15:41:44.047Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T13:16:49.717

Modified: 2026-08-28T15:46:19.387

Link: CVE-2025-62300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:32Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')