Description
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.
Published: 2026-07-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows attackers to receive detailed error messages from HCL Aftermarket EPC, leaking internal processing details. This exposure does not directly modify system state but provides information that could assist in crafting a more targeted attack, such as identifying configuration weaknesses or database structures. The issue stems from inadequate sanitization of error output and is classified as CWE-209.

Affected Systems

HCL Aftermarket EPC is affected. No specific version range is listed in the advisory, so any deployment of this product should be considered vulnerable until a fix is verified.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate impact, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely remote, occurring through the application's web interface when an error condition is triggered. The attacker would need to cause an error in order to receive the detailed message, but once the message is obtained they gain additional information that could facilitate subsequent attacks.

Generated by OpenCVE AI on July 31, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest HCL Aftermarket EPC patch that suppresses detailed error output.
  • Configure the application and web server to return generic error pages that do not disclose server‑side details; disable verbose error handling in production environments.
  • Review and limit access to error logs and internal diagnostics so that only authorized personnel can view them.

Generated by OpenCVE AI on July 31, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Detailed Error Message Disclosure in HCL Aftermarket EPC

Wed, 29 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Detailed Error Message Disclosure in HCL Aftermarket EPC

Sun, 26 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Detailed Error Message Information Disclosure in HCL Aftermarket EPC

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware aftermarket Epc
Vendors & Products Hclsoftware
Hclsoftware aftermarket Epc

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Detailed Error Message Information Disclosure in HCL Aftermarket EPC

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Aftermarket Epc
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-17T15:19:29.809Z

Reserved: 2024-01-18T07:29:59.076Z

Link: CVE-2024-23575

cve-icon Vulnrichment

Updated: 2026-07-17T15:19:24.679Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information