Clickjacking Vulnerability in HCL IEM Software
CVE-2026-56585

3.1LOW

What is CVE-2026-56585?

HCL IEM is vulnerable to an issue where the X-Frame-Options header is missing. This flaw enables attackers to embed the application within malicious web pages, potentially tricking users into executing actions without their knowledge. Ensuring proper header implementation is crucial for defending against clickjacking attacks and securing user interactions.

Affected Version(s)

IntelliOps Event Management 1.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.