Junglewise Threat Intelligence

CVE-2025-62343: HCL IntelliOps Event Management admin session concurrency vulnerability

CVE-2025-62343 · Severity: low · CVSS 3.1 · Published 2026-08-27

Vendors: HCL.

Executive brief

HCL IntelliOps Event Management (IEM) is a monitoring and alerting platform used to manage operational events across IT infrastructure. An admin session concurrency flaw allows user sessions to remain active even after logout or deletion, potentially giving attackers extended unauthorized access to the system if they compromise an admin account.

Technical details

The vulnerability is a session management flaw affecting HCL IntelliOps Event Management where user sessions may not properly terminate after logout or explicit session deletion. This allows concurrent sessions to persist beyond their intended lifetime, potentially enabling attackers who gain initial admin access to maintain a persistent foothold. The attack requires administrative credentials or an existing admin session; once compromised, an attacker could perform arbitrary administrative actions without being logged out. No patch details are available in the provided advisory materials.

Affected products

  • HCL IntelliOps Event Management

Timeline

  • 2026-08-27: disclosed

References