Impact
HCL Aftermarket EPC accepts HTTP requests without validating the HOST header, allowing attackers to inject arbitrary host values. This flaw can lead to host header poisoning, enabling phishing, session fixation, or other server misconfiguration attacks. The weakness corresponds to input validation failure as defined by CWE-20.
Affected Systems
The vulnerability affects HCLSoftware Aftermarket EPC. Specific product versions are not enumerated, so any deployed instance of this application is potentially impacted unless the service is patched or re‑configured to validate the HOST header.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the moderate range, while the EPSS score of less than 1% indicates that, at present, exploitation attempts are unlikely to be widespread. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. The likely attack vector is a crafted HTTP request sent to the vulnerable server with a malicious HOST header, which does not require authentication or privileged access.
OpenCVE Enrichment