Description
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
Published: 2026-08-20
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL IntelliOps Event Management has a flaw that omits critical information from its audit logs, breaking the auditability and observability of workflows. This weakness is identified as CWE-221, which represents an information exposure through log misconfiguration. As a result, if an attacker gains access to the system, the lack of proper logging could make it difficult for security teams to conduct incident response or forensic analysis, potentially allowing malicious activity to go undetected.

Affected Systems

The vulnerability affects HCL Software’s IntelliOps Event Management product. No specific affected versions are documented, so all deployments of this product should be considered potentially impacted until further detail is released.

Risk and Exploitability

The CVSS score of 5 indicates this flaw is of moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to have access to the application – either through remote authentication or local compromise – to exploit this omission. While the flaw does not provide a direct path to code execution or privilege escalation, the resulting loss of audit information could facilitate prolonged malicious activity and complicate detection and response.

Generated by OpenCVE AI on August 20, 2026 at 21:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the current version of HCL IntelliOps Event Management against the vendor’s latest advisories and apply any available patch or update.
  • Configure or enable additional application-level logging or external audit logging solutions to compensate for the missing audit trail.
  • Implement strict access controls and audit monitoring on the application to reduce the risk of unauthorized access that would enable exploitation of the missing logs.

Generated by OpenCVE AI on August 20, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcl Software
Hcl Software iem
Vendors & Products Hcl Software
Hcl Software iem

Thu, 20 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
Title HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
Weaknesses CWE-221
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Hcl Software Iem
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-20T15:26:26.432Z

Reserved: 2025-10-10T09:04:02.284Z

Link: CVE-2025-62306

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T13:16:49.837

Modified: 2026-08-28T15:46:19.387

Link: CVE-2025-62306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:34Z

Weaknesses
  • CWE-221

    Information Loss or Omission