Executive brief
HCL IntelliOps Event Management (IEM) is a workflow and event management platform used by organizations to automate incident response and operational tasks. The application lacks sufficient logging and audit trails, which prevents security teams from tracking who performed what actions and when. If an attacker gains access to the system, this logging gap significantly hampers incident response capabilities and forensic investigation, potentially allowing malicious activity to go undetected.
Technical details
This vulnerability is classified as information omission / insufficient logging (CWE-778). The root cause is inadequate logging mechanisms in HCL IntelliOps Event Management's workflow execution and event processing components. The attack vector is internal/post-authentication, requiring an attacker to first gain access to the application, after which they can perform actions that leave minimal audit traces. The impact is degraded auditability and observability, which reduces the ability to detect, investigate, and respond to security incidents. This is primarily a security monitoring and compliance impact rather than a direct confidentiality or integrity breach.
Affected products
- HCL IntelliOps Event Management
Timeline
- 2026-08-20: disclosed