Impact
The web server used by HCL Aftermarket EPC reveals the underlying server software name and version in HTTP responses. This information disclosure allows an attacker to identify the specific product and its version, a flaw that aligns with CWE‑200 (Information Exposure). Knowing the exact version can help an adversary determine which publicly documented vulnerabilities or weaknesses apply, especially if the software is out of date. The flaw does not grant direct code execution or privileged access, but it can be a valuable reconnaissance step for future attacks.
Affected Systems
HCL Software’s Aftermarket EPC product is affected. All installations that incorporate the exposed web server component remain vulnerable until the vendor issues a fix or the systems are upgraded. Any release that still includes the server version disclosure is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score of less than 1 % along with no listing in the CISA KEV catalog suggest that exploitation is currently unlikely. Nevertheless, the vulnerability appears to be remote and does not require authentication, inferred from the description that any Internet‑accessible instance can expose its server version. Attackers could gather version information from the HTTP header, which may then inform targeted exploitation of other known flaws in that specific version.
OpenCVE Enrichment