Impact
HCL Aftermarket EPC transmits confidential information via GET query parameters, causing the data to be embedded in URLs. As a result, the sensitive values may be recorded in server logs, browser history, or proxy logs, which are typically not treated as secure storage. If an attacker can access these records, the protected information can be disclosed. This weakness aligns with CWE‑804, which highlights the improper use of GET requests to carry sensitive data.
Affected Systems
The affected product is HCL Software’s Aftermarket EPC. No specific product version is listed; the flaw exists in any deployment that relies on query parameters to convey confidential information.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an ordinary user action or a deceptive link that triggers a GET request containing sensitive data; subsequent access to logs or history can reveal the information.
OpenCVE Enrichment