Impact
The vulnerability described in HCL Hive concerns weak software supply‑chain governance, which could allow the inclusion of vulnerable, unmaintained, or malicious third‑party dependencies within the application environment. Based on the description, an attacker who can influence the build or deployment pipeline may introduce compromised libraries that could affect Hive’s integrity or introduce malicious behavior. This weakness corresponds to CWE‑1104, indicating improper verification of third‑party components.
Affected Systems
The vendor is HCL Software, product Hive. No specific versions are listed in the supplied data; therefore, any installation of Hive that relies on external dependencies managed through its build or deployment processes is potentially affected. Without version information, all current and future Hive releases remain in the risk zone until further vendor clarification.
Risk and Exploitability
The CVSS score of 4.2 indicates low to moderate severity. The EPSS score is not available, so the likelihood of exploitation in the wild is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector, based on the description, is within the software build or deployment pipeline, meaning an attacker would need to compromise the supply‑chain tooling or supply chain output rather than directly attack a running Hive instance. As a result, organizations should focus on secure procurement and integrity checks of dependencies rather than expecting a direct exploit from the deployed application.
OpenCVE Enrichment