Hcltech Intelliops Event Management — known CVE vulnerabilities
Every CVE whose affected-product data names Hcltech Intelliops Event Management, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (9)
CVE-2026-56584 — CVSS 3.7 (low): HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and…
CVE-2026-56587 — CVSS 3.7 (low): HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle…
CVE-2025-0249 — CVSS 3.3 (low): HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers…
CVE-2026-56585 — CVSS 3.1 (low): HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious…
CVE-2026-56586 — CVSS 3.1 (low): HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle…
CVE-2025-0252 — CVSS 2.6 (low): HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially…
CVE-2025-0251 — CVSS 2.6 (low): HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user…
CVE-2025-0250 — CVSS 2.2 (low): HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being…
CVE-2025-0253 — CVSS 2.0 (low): HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could…