2026-08-24 13:42CVE-2025-68833HCL
PUBLISHED5.2CWE-1240

HCL Hive is affected by use of a cryptographic primitive with a risky implementation

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

Problem type

Affected products

HCLSoftware

HCL Hive

1.0 - AFFECTED

References

GitHub Security Advisories

GHSA-x278-8xqr-3rx2

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which...

https://github.com/advisories/GHSA-x278-8xqr-3rx2

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2025-68833
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2025-68833",
    "assignerOrgId": "1e47fe04-f25f-42fa-b674-36de2c5e3cfc",
    "assignerShortName": "HCL",
    "dateUpdated": "2026-08-24T13:42:32.436Z",
    "dateReserved": "2025-12-24T13:23:45.322Z",
    "datePublished": "2026-08-24T13:42:32.436Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1e47fe04-f25f-42fa-b674-36de2c5e3cfc",
        "shortName": "HCL",
        "dateUpdated": "2026-08-24T13:42:32.436Z"
      },
      "datePublic": "2026-08-24T12:10:00.000Z",
      "title": "HCL Hive is affected by use of a cryptographic primitive with a risky implementation",
      "descriptions": [
        {
          "lang": "en",
          "value": "HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.<br>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "HCLSoftware",
          "product": "HCL Hive",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-1240 Use of a cryptographic primitive with a risky implementation",
              "cweId": "CWE-1240",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131731"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM"
          }
        }
      ]
    }
  }
}