Impact
HCL IntelliOps Event Management is vulnerable to an Admin Session Concurrency issue that allows user sessions to remain active after a logout or explicit session deletion. This flaw means an attacker who already holds a valid session can keep that session alive or regain it without re-authentication, potentially extending the window of unauthorized access.
Affected Systems
The affected product is HCL Software’s HCL IntelliOps Event Management (IEM). No specific version range is indicated in the advisory, so all installations may be impacted until a vendor fix is applied.
Risk and Exploitability
With a CVSS score of 3.1 the flaw is considered low severity, but the absence of an EPSS score suggests that widespread exploitation is not anticipated. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is remote via the web interface, and successful exploitation would permit an attacker to maintain an administrative session after attempting to terminate it. While the impact does not provide immediate privilege escalation, the persistence of a session can facilitate further malicious actions if combined with other vulnerabilities or social engineering.
OpenCVE Enrichment