Executive brief
HCL iControl, a business process monitoring and management solution, is affected by a security flaw that fails to properly validate data inputs. An attacker with basic user access could exploit this to cause unexpected system behavior or bypass certain security controls. This could lead to unauthorized changes to system settings or data, potentially impacting the integrity of business operations.
Technical details
HCL iControl versions 4.3.0 and 4.4.0 contain an improper input validation vulnerability (CWE-20). The flaw exists in an architectural security tactic that fails to verify if received input matches the expected data type. An authenticated attacker with low privileges can exploit this over the network to trigger unexpected system states or bypass security checks. The impact is primarily limited to integrity, as indicated by the CVSS vector. Users are advised to refer to HCL security bulletin KB0132395 for remediation steps.
Affected products
- HCL iControl 4.3.0, 4.4.0
Timeline
- 2026-07-31: disclosed
- 2026-07-31: advisory