Description
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
Published: 2026-07-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because the HCL Aftermarket EPC server is not configured to send an X‑XSS‑Protection HTTP response header. The absence of this header allows a browser to execute potentially malicious scripts injected into page content, enabling reflected or stored cross‑site‑Scripting attacks that can compromise user data or session integrity. The weakness is a classic input validation flaw (CWE‑692).

Affected Systems

HCLSoftware Aftermarket EPC. No specific product versions are mentioned in the advisory, so all current releases of this product are considered potentially affected.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity vulnerability. The EPSS score is below 1%, suggesting that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would typically require an attacker to trick a user into loading crafted content, either through social engineering or by submitting malicious data to a vulnerable input field. The lack of an X‑XSS‑Protection header removes a layer of browser‑based mitigation, lowering the barrier for such XSS attacks.

Generated by OpenCVE AI on July 31, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HCL Aftermarket EPC to the latest patched version that includes X‑XSS‑Protection support.
  • Configure the application or underlying web server to add the X‑XSS‑Protection header to all HTTP responses.
  • Implement additional XSS defenses, such as a Content Security Policy header, to limit script execution domains.

Generated by OpenCVE AI on July 31, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Missing X‑XSS‑Protection Header Enables XSS in HCL Aftermarket EPC

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Missing X‑XSS‑Protection Header Enables XSS in HCL Aftermarket EPC

Sun, 26 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Missing X‑XSS‑Protection Header Allowing Potential XSS Attacks

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware aftermarket Epc
Vendors & Products Hclsoftware
Hclsoftware aftermarket Epc

Wed, 22 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Missing X‑XSS‑Protection Header Allowing Potential XSS Attacks

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
Weaknesses CWE-692
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Aftermarket Epc
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-17T15:22:26.200Z

Reserved: 2024-01-18T07:29:56.729Z

Link: CVE-2024-23569

cve-icon Vulnrichment

Updated: 2026-07-17T15:22:20.941Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-692

    Incomplete Denylist to Cross-Site Scripting