Executive brief
HCL IntelliOps Event Management, a platform used for monitoring and managing IT infrastructure events, fails to enforce HTTP Strict Transport Security (HSTS). This oversight could allow an attacker to intercept and view sensitive communications between a user's browser and the management console. In practice, this means an attacker on the same network could potentially capture login credentials or other private data by forcing the connection to use an unencrypted format.
Technical details
HCL IntelliOps Event Management (IEM) version 1.1 is vulnerable to CWE-523 (Unprotected Transport of Credentials) because it does not enforce HTTP Strict Transport Security (HSTS). This missing security header allows a network-positioned attacker to perform SSL stripping or man-in-the-middle (MITM) attacks by intercepting the initial unencrypted HTTP request and preventing the browser from upgrading to a secure HTTPS connection. If successful, the attacker can capture sensitive information, such as session tokens or credentials, transmitted in plain text. The vulnerability is rated low severity (CVSS 3.7) due to the high attack complexity required to intercept traffic in a typical network environment.
Affected products
- HCL Software IntelliOps Event Management 1.1
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-56587
- 2026-07-21: advisory: HCL Software published security bulletin KB0132378