Impact
HCL Hive exposes its Swagger API documentation publicly, providing unauthenticated users with full access to API endpoint definitions. The disclosed documentation does not contain credentials or personally identifiable information, yet exposing such internal API details increases the attack surface by enabling reconnaissance and facilitating the planning of further attacks. The weakness is classified as CWE‑215 (Information Exposure).
Affected Systems
The vulnerability applies to HCL Software’s HCL Hive platform. No specific affected versions are listed in the advisory; users should consult the vendor’s support documentation for the precise affected releases.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as low severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, indicating a relatively low exploitation probability. Exploitation requires no special privileges; an attacker simply accesses the publicly reachable Swagger endpoint to gather API metadata. While the immediate risk is limited to information disclosure and heightened reconnaissance capabilities, the additional exposure could aid attackers in crafting subsequent attacks against other components of HCL Hive.
OpenCVE Enrichment