Impact
HCL IntelliOps Event Management (IEM) has a flaw in its nginx server that exposes version information. This disclosure can allow an attacker to discover which software version is running and then use that knowledge to target other known vulnerabilities or exploits. The weakness is a classic information disclosure issue (CWE-200).
Affected Systems
The affected product is HCLSoftware IntelliOps Event Management, specifically the component that runs nginx. No specific version range is listed, so any installation that includes the implicated nginx configuration may be vulnerable.
Risk and Exploitability
The CVSS score for this vulnerability is 3.7, indicating low severity. Exploitation is unlikely to be heavily automated, as the EPSS score is less than 1%. The vulnerability is not listed in the CISA KEV catalog. Potential attackers likely need to observe the server externally, and the lack of authentication or privilege requirements makes it easy to gather the exposed information. While the immediate risk is limited, this disclosure increases the attack surface by revealing characteristics that can aid in planning more serious attacks.
OpenCVE Enrichment