Executive brief
HCL IntelliOps Event Management, a tool used for monitoring and managing IT infrastructure events, is missing a security configuration that helps prevent web browsers from misinterpreting file types. This oversight could potentially allow an attacker to perform man-in-the-middle attacks, leading to the interception of sensitive data or unauthorized changes to information. While the risk is rated as low, it represents a weakness in how the application secures its communications with users.
Technical details
HCL IntelliOps Event Management (IEM) version 1.1 fails to implement the 'X-Content-Type-Options: nosniff' HTTP response header. This configuration weakness (CWE-16) allows browsers to perform MIME-type sniffing, which can be leveraged by a network-based attacker to execute man-in-the-middle (MITM) or SSL stripping attacks. By forcing a browser to interpret a response as a different content type than intended, an attacker may intercept sensitive data or perform unauthorized modifications. The attack requires a high degree of complexity and user interaction to be successful.
Affected products
- HCL Software IntelliOps Event Management 1.1
Timeline
- 2026-07-21: advisory: Initial advisory published by HCL Software and NVD.