Description
HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion.
Published: 2026-08-27
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL IntelliOps Event Management is vulnerable to an Admin Session Concurrency issue that allows user sessions to remain active after a logout or explicit session deletion. This flaw means an attacker who already holds a valid session can keep that session alive or regain it without re-authentication, potentially extending the window of unauthorized access.

Affected Systems

The affected product is HCL Software’s HCL IntelliOps Event Management (IEM). No specific version range is indicated in the advisory, so all installations may be impacted until a vendor fix is applied.

Risk and Exploitability

With a CVSS score of 3.1 the flaw is considered low severity, but the absence of an EPSS score suggests that widespread exploitation is not anticipated. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is remote via the web interface, and successful exploitation would permit an attacker to maintain an administrative session after attempting to terminate it. While the impact does not provide immediate privilege escalation, the persistence of a session can facilitate further malicious actions if combined with other vulnerabilities or social engineering.

Generated by OpenCVE AI on August 27, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor-released security patch or upgrade to the latest HCL IntelliOps Event Management version that addresses session concurrency issues
  • Through the administrative console, force logout or delete all active sessions for users and review session audit logs to detect anomalous persistence
  • Configure or enforce session timeout policies to eliminate idle or expired sessions and disable concurrent session support if it is not required
  • Lastly, verify that the application correctly invalidates session tokens immediately upon logout or explicit session deletion

Generated by OpenCVE AI on August 27, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion.
Title HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
Weaknesses CWE-557
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-27T19:43:13.337Z

Reserved: 2025-10-10T09:04:27.771Z

Link: CVE-2025-62343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T17:17:05.707

Modified: 2026-08-27T20:17:01.797

Link: CVE-2025-62343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T17:30:12Z

Weaknesses