Impact
HCL IntelliOps Event Management is vulnerable to insufficient logging, meaning that the system does not record enough detail about operations. This weakness reduces the ability to trace actions, diminish accountability, and makes it easier for an attacker to probe user privileges without detection. The impact is primarily the erosion of audit trails and the potential for stealthy or unauthorized activity to persist undetected.
Affected Systems
The affected product is HCL IntelliOps Event Management (IEM) from HCL Software. No specific version information is supplied.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity level. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, there is no evidence that it has been actively exploited in the wild. However, the inferred attack scenario is that an attacker could use privilege probing or other malicious activity that would bypass visible detection due to the lack of sufficient logs. The threat lies in reduced visibility rather than a direct code execution vector.
OpenCVE Enrichment