Executive brief
HCL IntelliOps Event Management (IEM) is a platform used to monitor and manage IT operations events. A session handling vulnerability allows user sessions to persist after logout or deletion, potentially allowing unauthorized access to user accounts or sensitive operations if sessions are not properly terminated.
Technical details
The vulnerability is a session management flaw in HCL IntelliOps Event Management where user sessions are not fully terminated following logout or deletion operations. This is an improper session invalidation issue that allows session tokens or identifiers to remain valid after the user attempts to end their session. An authenticated attacker or user who gains access to another user's session identifier could potentially reuse that session to impersonate the user. Exploitation requires knowledge of a valid session identifier but no network-level attack is needed once a session is compromised. The vulnerability is classified as medium severity with a CVSS score of 6.4.
Affected products
- HCL IntelliOps Event Management
Timeline
- 2026-08-27: disclosed