Impact
HCL Hive is affected by infrastructure and network configuration weaknesses that allow an attacker to move laterally across the internal network, escape from container boundaries, and expose sensitive data. The flaw is categorized as CWE‑1004, indicating that permission or configuration controls are insufficient or incorrectly applied, enabling unauthorized access. The direct consequences are loss of confidentiality and integrity, because an internal or compromised user can access resources beyond intended boundaries.
Affected Systems
The product impacted is HCL Software’s Hive. No specific version information is provided in the advisory, so all supported releases of Hive are potentially vulnerable unless a patch has been applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.4, indicating moderate severity. The EPSS score is not available, so the precise likelihood of exploitation cannot be quantified, but the risk is still notable because an attacker who gains lateral movement can compromise multiple components. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits in the wild yet. Based on the description, the likely attack vector involves misconfigured infrastructure or network settings, which an attacker would exploit from a privileged internal position or through compromised credentials.
OpenCVE Enrichment