Least Privileges Violation in HCL IntelliOps Event Management
CVE-2025-62299

6.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2025-62299?

HCL IntelliOps Event Management (IEM) is susceptible to a least privileges violation that can potentially enable an attacker to gain elevated access to resources. This misconfiguration may allow unauthorized users to leverage their original privileges to access sensitive information or perform actions that should be restricted. Organizations utilizing HCL IEM should take immediate steps to investigate and remediate this vulnerability to safeguard against potential exploitation.

Affected Version(s)

IEM v1.4.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.