Description
HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.
Published: 2026-03-26
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: Data exposure and unauthorized API access
Action: Patch Now
AI Analysis

Impact

The vulnerability is a Cross-Origin Resource Sharing misconfiguration that allows attackers to access sensitive user information, interact with APIs without proper authorization, and potentially manipulate or leak data. Exploitation could enable theft of private data and execution of actions on behalf of a legitimate user. This weakness corresponds to CWE-942, indicating information exposure through external authentication or authorization.

Affected Systems

The affected product is HCL Aftermarket DPC, version 1.0.0. The issue is present in the CPE identified as hcltech:aftermarket_cloud:1.0.0 and reported by HCL as a vulnerability in the Aftermarket DPC software suite.

Risk and Exploitability

The CVSS score of 2.6 indicates a low overall risk, but the potential for data theft and malicious API use offers tangible impact. Although no EPSS score is available and the vulnerability is not listed in CISA KEV, the likelihood of exploitation remains plausible because an attacker can trigger the misconfigured CORS settings via a malicious website or script. Mitigation should therefore be prioritized despite the low severity rating.

Generated by OpenCVE AI on March 26, 2026 at 21:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the HCL support article KB0129793 for guidance on addressing the CORS vulnerability
  • Restrict CORS allowed origins to trusted domains only and remove any wildcard "*" settings
  • Configure CORS headers to specify only the required methods and headers
  • Test the updated CORS configuration in a controlled staging environment before deploying to production
  • Monitor application logs for unexpected cross-origin requests to detect potential abuse

Generated by OpenCVE AI on March 26, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 27 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcl
Hcl aftermarket Dpc
Vendors & Products Hcl
Hcl aftermarket Dpc

Thu, 26 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech aftermarket Cloud
CPEs cpe:2.3:a:hcltech:aftermarket_cloud:1.0.0:*:*:*:*:*:*:*
Vendors & Products Hcltech
Hcltech aftermarket Cloud

Thu, 26 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
Description HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.
Title HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability
Weaknesses CWE-942
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Hcl Aftermarket Dpc
Hcltech Aftermarket Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-03-26T15:02:00.121Z

Reserved: 2025-08-12T07:00:17.742Z

Link: CVE-2025-55274

cve-icon Vulnrichment

Updated: 2026-03-26T13:43:54.110Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-26T13:16:27.033

Modified: 2026-03-26T20:19:07.570

Link: CVE-2025-55274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:28:35Z

Weaknesses