Impact
The vulnerability arises because the HCL Aftermarket EPC server is not configured to send an X‑XSS‑Protection HTTP response header. The absence of this header allows a browser to execute potentially malicious scripts injected into page content, enabling reflected or stored cross‑site‑Scripting attacks that can compromise user data or session integrity. The weakness is a classic input validation flaw (CWE‑692).
Affected Systems
HCLSoftware Aftermarket EPC. No specific product versions are mentioned in the advisory, so all current releases of this product are considered potentially affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity vulnerability. The EPSS score is below 1%, suggesting that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would typically require an attacker to trick a user into loading crafted content, either through social engineering or by submitting malicious data to a vulnerable input field. The lack of an X‑XSS‑Protection header removes a layer of browser‑based mitigation, lowering the barrier for such XSS attacks.
OpenCVE Enrichment