Impact
The vulnerability allows attackers to receive detailed error messages from HCL Aftermarket EPC, leaking internal processing details. This exposure does not directly modify system state but provides information that could assist in crafting a more targeted attack, such as identifying configuration weaknesses or database structures. The issue stems from inadequate sanitization of error output and is classified as CWE-209.
Affected Systems
HCL Aftermarket EPC is affected. No specific version range is listed in the advisory, so any deployment of this product should be considered vulnerable until a fix is verified.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely remote, occurring through the application's web interface when an error condition is triggered. The attacker would need to cause an error in order to receive the detailed message, but once the message is obtained they gain additional information that could facilitate subsequent attacks.
OpenCVE Enrichment