Impact
An information‑disclosure flaw in HCL Hive allows an adversary to learn details about the host environment, potentially revealing sensitive configuration data or system attributes. The weakness is a classic data‑leak condition that could assist attackers in crafting further attacks or compromising surrounding infrastructure. This vulnerability is catalogued as CWE‑200.
Affected Systems
The defect affects the HCL Software Hive product. No specific version numbers are listed in the CNA data, so the vulnerability could apply to any installed instance of Hive that has not been updated to a patched release. Administrators should verify the exact version in use and cross‑check with HCL’s support resources for applicable patches.
Risk and Exploitability
With a CVSS score of 3.7 the severity is considered low, and there is no EPSS data available to gauge exploitation likelihood. The vulnerability is not present in the CISA KEV catalog, indicating that no widespread exploits have been reported. However, an attacker who can harness this information leak may use it to aid more targeted attacks. The exposure is local or network‑limited; an attacker would need some degree of access to the Hive interface or to the host system. While the flaw alone does not provide privilege escalation or remote code execution, the disclosed data can aid reconnaissance efforts that could lead to higher‑impact exploits.
OpenCVE Enrichment