Impact
HCL IntelliOps Event Management (IEM) contains a session deletion flaw that causes user sessions to remain active after a logout or session‑clearing action. The flaw falls under CWE-613, indicating that session data is not properly cleared and can be reused. An attacker with an existing session or the ability to trigger the deletion process could maintain unauthorized access, potentially performing actions allowed by the session. This constitutes a moderate‑risk vulnerability with a CVSS score of 6.4.
Affected Systems
The vulnerability affects HCL Software’s IntelliOps Event Management component across supported editions. No specific release identifiers are listed, so all deployments of IEM should be reviewed. The vendor has identified the issue in the IEM product line.
Risk and Exploitability
The exploitability metric is currently not quantified via EPSS. The vulnerability is not recorded in the CISA KEV catalog, but its CVSS score indicates a moderate risk. Attackers would require authenticated context to invoke a logout or session‑deletion operation; consequently the attack vector is likely intra‑system or from a trusted user context. If an attacker can suspend normal session invalidation, any remaining session could be used to access protected resources. Given its moderate severity and lack of publicly documented exploitation, the threat remains moderate but should be addressed promptly to avoid potential session hijacking.
OpenCVE Enrichment