HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-9725 | HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 10 Oct 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hcltech
Hcltech traveler |
|
CPEs | cpe:2.3:a:hcltech:traveler:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hcltech
Hcltech traveler |
Mon, 07 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 03 Apr 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks. | |
Title | HCL Traveler is affected by generation of error messages containing sensitive information | |
Weaknesses | CWE-209 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-04-07T16:31:57.411Z
Reserved: 2025-01-06T16:01:36.580Z
Link: CVE-2025-0279

Updated: 2025-04-07T16:31:50.571Z

Status : Analyzed
Published: 2025-04-03T22:15:16.700
Modified: 2025-10-10T16:47:02.997
Link: CVE-2025-0279

No data.

No data.