Executive brief
HCL IntelliOps Event Management, a tool used for monitoring and managing IT infrastructure events, is affected by a configuration issue that reveals internal server version information. An attacker can use this information to identify that the software is outdated, helping them plan more sophisticated attacks against known weaknesses. While this does not directly grant access to data, it provides a roadmap for attackers to target the system more effectively.
Technical details
An information disclosure vulnerability exists in HCL IntelliOps Event Management (IEM) version 1.1 due to improper configuration of the underlying Nginx server. The server headers or error pages reveal specific version information (CWE-200), which can be harvested by unauthenticated remote attackers. While the attack complexity is considered high, the disclosure of these details facilitates reconnaissance, allowing an attacker to identify known vulnerabilities or publicly available exploits applicable to the specific software versions in use. Users are advised to consult HCL security bulletin KB0132378 for remediation steps.
Affected products
- HCL Software IntelliOps Event Management (IEM) 1.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by HCL Software
- 2026-07-21: advisory: NVD record published