Impact
Missing or insecure Cross‑Origin Security headers allow the application’s environment and resources to be accessed by unauthenticated or malicious domains. This vulnerability can let an attacker issue requests to the application from unauthorized origins, potentially reading sensitive data or manipulating state. The flaw is a typical confidentiality issue (CWE‑200).
Affected Systems
HCL Software’s IntelliOps Event Management (IEM) product. No specific version data is provided, so all deployments of IEM remain potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate risk level. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV. Attacking the flaw requires only the ability to craft a cross‑origin request, making external exploitation plausible wherever the IEM interface is exposed over the Internet. Given the lack of mitigation, this vulnerability could be leveraged wherever the application accepts HTTP requests from external clients.
OpenCVE Enrichment