Impact
The vulnerability involves the absence of the X‑Content‑Type‑Options header, making the HCL IntelliOps Event Management application susceptible to SSL stripping or man‑in‑the‑middle attacks. Attackers could intercept or modify traffic, potentially exposing sensitive information, without executing code or gaining privileged access. The flaw is a configuration management weakness classified as CWE‑16.
Affected Systems
The affected environment is the HCLSoftware IntelliOps Event Management product. The specific version range of the vulnerable deployment is not disclosed in the provided data, so all installations of the product should be reviewed for the presence of the header.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score is below 1%, suggesting this flaw is rarely exploited. It is not listed in the CISA KEV catalog. An attacker would need to intercept traffic to the IEM environment, typically over an insecure or compromised network, to exploit the missing header. The vulnerability can be leveraged by any client that connects to the system without strong certificate validation.
OpenCVE Enrichment