Description
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL IntelliOps Event Management (IEM) has a flaw in its nginx server that exposes version information. This disclosure can allow an attacker to discover which software version is running and then use that knowledge to target other known vulnerabilities or exploits. The weakness is a classic information disclosure issue (CWE-200).

Affected Systems

The affected product is HCLSoftware IntelliOps Event Management, specifically the component that runs nginx. No specific version range is listed, so any installation that includes the implicated nginx configuration may be vulnerable.

Risk and Exploitability

The CVSS score for this vulnerability is 3.7, indicating low severity. Exploitation is unlikely to be heavily automated, as the EPSS score is less than 1%. The vulnerability is not listed in the CISA KEV catalog. Potential attackers likely need to observe the server externally, and the lack of authentication or privilege requirements makes it easy to gather the exposed information. While the immediate risk is limited, this disclosure increases the attack surface by revealing characteristics that can aid in planning more serious attacks.

Generated by OpenCVE AI on July 30, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest HCL IntelliOps Event Management release that removes the nginx version disclosure, as documented in the vendor support article.
  • If a patch cannot be applied immediately, block external access to the nginx service using firewall rules or network segmentation to prevent unauthorized probing.
  • Follow vendor guidance to harden nginx configuration, such as disabling the "Server" header or setting it to a generic value.

Generated by OpenCVE AI on July 30, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech intelliops Event Management
Vendors & Products Hcltech
Hcltech intelliops Event Management

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.
Title HCL IEM was affected with the Information disclosure nginx server
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Intelliops Event Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-22T18:27:53.505Z

Reserved: 2026-06-22T13:39:56.746Z

Link: CVE-2026-56584

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:32.334Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor