Description
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.
Published: 2026-08-20
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure and unauthorized external interaction via missing or insecure Cross‑Origin Security headers
Action: Immediate Patch
AI Analysis

Impact

Missing or insecure Cross‑Origin Security headers allow the application’s environment and resources to be accessed by unauthenticated or malicious domains. This vulnerability can let an attacker issue requests to the application from unauthorized origins, potentially reading sensitive data or manipulating state. The flaw is a typical confidentiality issue (CWE‑200).

Affected Systems

HCL Software’s IntelliOps Event Management (IEM) product. No specific version data is provided, so all deployments of IEM remain potentially vulnerable.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate risk level. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV. Attacking the flaw requires only the ability to craft a cross‑origin request, making external exploitation plausible wherever the IEM interface is exposed over the Internet. Given the lack of mitigation, this vulnerability could be leveraged wherever the application accepts HTTP requests from external clients.

Generated by OpenCVE AI on August 20, 2026 at 22:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or update to HCL IntelliOps Event Management released by HCL.
  • Configure or enforce proper Cross‑Origin Security headers such as Content‑Security‑Policy, X‑Frame‑Options, and/or Access‑Control‑Allow‑Origin to restrict allowed origins.
  • Validate implementation with an automated security scanner or manual header inspection.

Generated by OpenCVE AI on August 20, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcl Software
Hcl Software iem
Vendors & Products Hcl Software
Hcl Software iem

Thu, 20 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.
Title HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Hcl Software Iem
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-27T16:06:38.928Z

Reserved: 2026-01-05T16:08:02.276Z

Link: CVE-2026-21784

cve-icon Vulnrichment

Updated: 2026-08-27T15:43:22.569Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T13:17:05.103

Modified: 2026-08-28T16:08:09.497

Link: CVE-2026-21784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:29Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor