Impact
HCL Aftermarket EPC does not guard the HTTP OPTIONS method, which returns a list of supported HTTP verbs. The information revealed can help an attacker map the attack surface and craft more targeted requests, potentially leading to additional exploits. The vulnerability is a configuration flaw identified by CWE-692.
Affected Systems
The affected product is HCLSoftware Aftermarket EPC. No specific version data is provided, so all installations of this product are potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is less than 1 percent, showing a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an attacker can trigger the flaw remotely using any outbound HTTP connection to the web server without authentication. Because the method is enabled by default, it is likely that exploiting it requires no special privileges, making it an attractive reconnaissance step for attackers.
OpenCVE Enrichment