Description
HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in a missing Strict‑Transport‑Security (S‑TLS) policy, allowing attackers to strip SSL or perform man‑in‑the‑middle attacks and compromise secure communications. The weakness is identified as CWE‑523, a failure to enforce mandatory HTTPS . Without the HSTS header, an attacker can downgrade connections to HTTP, intercept traffic, and potentially inject malicious content.

Affected Systems

Affected product: HCLSoftware IntelliOps Event Management (IEM). No specific version range is supplied in the advisory, so all deployed instances of IEM without a recent HSTS implementation should be considered vulnerable.

Risk and Exploitability

The CVSS score of 3.7 places the vulnerability in a low‑to‑moderate severity range, and the EPSS score of less than 1% indicates that active exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via a network or web attack that exploits the lack of HSTS headers to force a downgrade of secure connections, enabling passive or active interception of traffic.

Generated by OpenCVE AI on July 30, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce the Strict‑Transport‑Security header (e.g., Strict-Transport-Security:max-age=63072000; includeSubDomains; preload) on all HTTPS responses from the IEM application.
  • Redirect all HTTP requests to HTTPS or block HTTP traffic entirely to prevent downgrade attempts.
  • Apply any vendor‑issued patch or upgrade to a version of HCL IntelliOps Event Management that includes HSTS enforcement, following the official advisory from HCL Software.

Generated by OpenCVE AI on July 30, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech intelliops Event Management
Vendors & Products Hcltech
Hcltech intelliops Event Management

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.
Title HCL IEM was affected with Strict transport security not enforced
Weaknesses CWE-523
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Intelliops Event Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-22T18:27:48.179Z

Reserved: 2026-06-22T13:39:56.746Z

Link: CVE-2026-56587

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:33.652Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses
  • CWE-523

    Unprotected Transport of Credentials