X-Content-Type-Options Header Missing in HCL Software Product
CVE-2026-56586

3.1LOW

What is CVE-2026-56586?

The absence of the X-Content-Type-Options header in HCL IEM exposes users to potential threats such as SSL stripping and man-in-the-middle attacks. This vulnerability allows malicious actors to intercept and manipulate sensitive data transmitted over the network, compromising the security of user interactions with the application. Implementing this header is crucial for enhancing security posture and protecting users from evolving cyber threats.

Affected Version(s)

IntelliOps Event Management 1.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.