CVE-2025-0250
BaseFortify
Publication date: 2025-07-25
Last updated on: 2025-10-09
Assigner: HCL Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcltech | intelliops_event_management | 1.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in HCL IEM involves an authorization token sent in a cookie that is handled in a way that may increase its exposure to security risks. Essentially, the token used for authentication and authorization might be more easily accessed or intercepted due to how it is managed.
How can this vulnerability impact me? :
The vulnerability could potentially allow unauthorized parties to gain access to the authorization token, which might lead to limited exposure of confidential information or unauthorized access. However, the CVSS score indicates a low impact with only a low confidentiality impact and no integrity or availability impact.