Impact
HCL Hive has a flaw in which default permissions are set incorrectly, giving users or services more access than intended. This misconfiguration can allow a threat actor to move laterally across the environment, escape from restricted containers, and capture confidential internal traffic. The weakness falls under CWE‑276, an insecure permission assignment issue, and if exploited the attacker could compromise multiple services and exfiltrate sensitive data without needing privileged credentials.
Affected Systems
The vulnerability affects HCL Software’s HCL Hive platform. Specific product and version information are not disclosed in the available data, so any installation of HCL Hive that has not been patched to correct the default permissions is potentially susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates substantial risk. While the EPSS score is not provided, the lack of a KEV listing suggests no widespread exploitation has been documented to date. The likely attack vector is an attacker who has already established some foothold, such as a compromised user or container, and who can then leverage the permissive settings to move laterally, break out of container boundaries, or intercept internal communications.
OpenCVE Enrichment