CVE-2025-62306: HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
An attacker must first gain access to the HCL IntelliOps Event Management application. The reported impact is that insufficient logging can hinder incident response after such access.
Does this issue directly expose data or disrupt availability?
The provided severity vector indicates no direct confidentiality or availability impact. It indicates low integrity impact and a changed scope, while the description specifically emphasizes reduced auditability and observability.
How can teams determine whether they are affected?
Review the referenced HCL support advisory, KB0132456, for product-specific applicability and remediation information. The provided data does not identify affected versions or configurations.