Impact
HCL IntelliOps Event Management fails to set the X-Frame-Options header, an omission that classifies as CWE-693 (Missing Authentication). This allows the application to be embedded in malicious web pages, enabling attackers to trick users into performing unintended actions within the application, such as submitting sensitive data or executing administrative commands, without the users realizing they are interacting with a compromised interface.
Affected Systems
The vulnerability affects HCLSoftware IntelliOps Event Management. No specific product versions are listed in the available data, so all deployments of this application should be considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious webpage that embeds the application in an iframe to perform clickjacking; this requires that a user visits the malicious page and interacts with the embedded interface. No additional technical prerequisites are stated in the source.
OpenCVE Enrichment