Impact
HCL Hive incorporates third‑party components that contain publicly documented security flaws. This use of vulnerable components can allow an attacker to gain unauthorized access or otherwise compromise the system. The weakness arises from the integration of untrusted code and is classified as CWE‑1104.
Affected Systems
The affected application is HCL Hive from HCLSoftware. No specific release or version ranges are listed, so the vulnerability may affect any installation that includes the vulnerable third‑party libraries.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, reflecting significant impact if successful exploitation results in unauthorized access. The EPSS score is not available, but the lack of a KEV listing suggests that active exploitation is not currently widespread. The risk remains substantial because the attacker only needs to exploit a known flaw in a third‑party component, which may be possible over a network interface exposed by HCL Hive.
OpenCVE Enrichment