Impact
The vulnerability allows an unauthenticated or low‑privileged user to inject unverified or malicious code directly into a production HCL Hive environment. The impact is the potential loss of confidentiality, integrity, or availability of the data and services running on the affected system, as the attacker can alter or compromise application functionality.
Affected Systems
The affected product is HCL Hive, a data processing and analytics platform from HCL Software. No specific versions are listed in the CNA data, so all installations of HCL Hive are considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score is not available, so exploitation probability cannot be quantified, but the vulnerability is listed as not part of the CISA KEV catalog. The likely attack vector is remote, requiring access to the HCL Hive web interface or management console, and the attacker must discover the broken access control to inject code. If exploited, the attacker could gain elevated privileges or execute arbitrary code within the Hive environment.
OpenCVE Enrichment