Description
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.
Published: 2026-07-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The web server used by HCL Aftermarket EPC reveals the underlying server software name and version in HTTP responses. This information disclosure allows an attacker to identify the specific product and its version, a flaw that aligns with CWE‑200 (Information Exposure). Knowing the exact version can help an adversary determine which publicly documented vulnerabilities or weaknesses apply, especially if the software is out of date. The flaw does not grant direct code execution or privileged access, but it can be a valuable reconnaissance step for future attacks.

Affected Systems

HCL Software’s Aftermarket EPC product is affected. All installations that incorporate the exposed web server component remain vulnerable until the vendor issues a fix or the systems are upgraded. Any release that still includes the server version disclosure is at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, and the EPSS score of less than 1 % along with no listing in the CISA KEV catalog suggest that exploitation is currently unlikely. Nevertheless, the vulnerability appears to be remote and does not require authentication, inferred from the description that any Internet‑accessible instance can expose its server version. Attackers could gather version information from the HTTP header, which may then inform targeted exploitation of other known flaws in that specific version.

Generated by OpenCVE AI on July 31, 2026 at 00:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that disables server version disclosure.
  • Disable or obfuscate the Server HTTP response header on the web server to hide version details.
  • Upgrade to the latest HCL Aftermarket EPC release, which removes the disclosure of server version information.

Generated by OpenCVE AI on July 31, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Version Information Disclosure in HCL Aftermarket EPC

Sun, 26 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Version Information Disclosure in HCL Aftermarket EPC

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware aftermarket Epc
Vendors & Products Hclsoftware
Hclsoftware aftermarket Epc

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Hclsoftware Aftermarket Epc
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-17T15:17:21.200Z

Reserved: 2024-01-18T07:29:56.729Z

Link: CVE-2024-23568

cve-icon Vulnrichment

Updated: 2026-07-17T15:17:16.768Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor