Description
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.
Published: 2026-07-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL Aftermarket EPC suffers a clickjacking vulnerability that arises from allowing the application to be embedded in an iframe on a malicious site through cross‑frame scripting. This flaw can enable an attacker to trick users into performing unintended actions, to hijack sessions, or to expose sensitive data. The weakness is a classic information exposure issue (CWE‑200).

Affected Systems

The affected system is HCLSoftware's Aftermarket EPC. No specific version numbers are supplied, so all currently deployed instances of this product are potentially impacted.

Risk and Exploitability

The CVSS score of 4.3 places the flaw in the moderate range, and the EPSS score of less than 1 % indicates a low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is web‑based, requiring an attacker to host a malicious site that loads the vulnerable application in an iframe. If the victim interacts with the iframe, the attacker could potentially phish, perform CSRF, or leak data, but actual exploitation is considered unlikely under current conditions.

Generated by OpenCVE AI on July 31, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure the application or web server to send an X‑Frame‑Options header of SAMEORIGIN or DENY to block framing by external sites.
  • Add a Content‑Security‑Policy frame‑ancestors directive pointing only to trusted origins.
  • Check with HCL Software for any pending updates or advisories that address this vulnerability.

Generated by OpenCVE AI on July 31, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Clickjacking Vulnerability in HCL Aftermarket EPC Exposes Sensitive Information

Wed, 29 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Clickjacking Vulnerability in HCL Aftermarket EPC

Fri, 24 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Clickjacking Vulnerability in HCL Aftermarket EPC

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware aftermarket Epc
Vendors & Products Hclsoftware
Hclsoftware aftermarket Epc

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Hclsoftware Aftermarket Epc
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-17T15:23:23.683Z

Reserved: 2024-01-18T07:29:59.076Z

Link: CVE-2024-23570

cve-icon Vulnrichment

Updated: 2026-07-17T15:23:18.463Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor