Impact
HCL Aftermarket EPC sets a cookie that apparently contains a session token, a weakness that could expose authenticated session credentials. The vulnerability is classified as CWE‑614. The CVE text indicates that having the token in the cookie may raise risk, but it does not confirm that the token is actively used for authentication. The impact is limited to potential session hijacking if the token is captured or forged.
Affected Systems
The affected product is HCL Software Aftermarket EPC. No version information is supplied, so all releases of the product are considered potentially affected until a vendor patch is released. Users should check HCL’s support site for updates.
Risk and Exploitability
The CVSS score of 4.2 ranks the issue as low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. The attack vector is inferred to involve obtaining the cookie through client‑side or network means, but this inference is not explicitly stated in the CVE data.
OpenCVE Enrichment