Impact
HCL IntelliOps Event Management has a flaw that omits critical information from its audit logs, breaking the auditability and observability of workflows. This weakness is identified as CWE-221, which represents an information exposure through log misconfiguration. As a result, if an attacker gains access to the system, the lack of proper logging could make it difficult for security teams to conduct incident response or forensic analysis, potentially allowing malicious activity to go undetected.
Affected Systems
The vulnerability affects HCL Software’s IntelliOps Event Management product. No specific affected versions are documented, so all deployments of this product should be considered potentially impacted until further detail is released.
Risk and Exploitability
The CVSS score of 5 indicates this flaw is of moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to have access to the application – either through remote authentication or local compromise – to exploit this omission. While the flaw does not provide a direct path to code execution or privilege escalation, the resulting loss of audit information could facilitate prolonged malicious activity and complicate detection and response.
OpenCVE Enrichment