Executive brief
HCL iControl, a business process monitoring and management solution, is affected by a security flaw that exposes internal configuration files. This exposure is caused by insufficient hardening of the web server or application settings. An attacker with local access to the system could view sensitive configuration data, which might lead to further unauthorized access or insights into the system's internal operations.
Technical details
HCL iControl versions 4.3.0 and 4.4.0 are vulnerable to sensitive data exposure (CWE-497). The vulnerability stems from improper web server or application hardening, which fails to restrict access to internal configuration files. According to the CVSS vector, the attack vector is local (AV:L), meaning an attacker requires local access to the environment to exploit the flaw. Successful exploitation allows an unauthorized party to read sensitive system information, potentially revealing configuration details that could be used in subsequent attacks. Users are advised to refer to HCL Software's security bulletin KB0132395 for remediation steps.
Affected products
- HCL Software iControl 4.3.0, 4.4.0
Timeline
- 2026-07-31: advisory: Initial disclosure by HCL Software and NVD publication.