Impact
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control, which could allow an attacker to gain unauthorized access to resources. The vulnerability is classified under CWE‑1240, which is related to improper handling of cryptographic contexts, but the description focuses on access control weaknesses rather than cryptographic manipulation. An attacker who can authenticate or manipulate access tokens may read or alter confidential data beyond their intended scope.
Affected Systems
HCL Software’s HCL Hive Keycloak IAM instance is affected. No specific product versions are listed in the data; any installation of HCL Hive should be evaluated for this flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting that it is not currently a high‑profile exploit target. Based on the description, it is inferred that an attacker could exploit the IAM component’s access control granularity by forging or manipulating authentication tokens to access resources beyond their intended scope.
OpenCVE Enrichment