Impact
The vulnerability is a Cross-Origin Resource Sharing misconfiguration that allows attackers to access sensitive user information, interact with APIs without proper authorization, and potentially manipulate or leak data. Exploitation could enable theft of private data and execution of actions on behalf of a legitimate user. This weakness corresponds to CWE-942, indicating information exposure through external authentication or authorization.
Affected Systems
The affected product is HCL Aftermarket DPC, version 1.0.0. The issue is present in the CPE identified as hcltech:aftermarket_cloud:1.0.0 and reported by HCL as a vulnerability in the Aftermarket DPC software suite.
Risk and Exploitability
The CVSS score of 2.6 indicates a low overall risk, but the potential for data theft and malicious API use offers tangible impact. Although no EPSS score is available and the vulnerability is not listed in CISA KEV, the likelihood of exploitation remains plausible because an attacker can trigger the misconfigured CORS settings via a malicious website or script. Mitigation should therefore be prioritized despite the low severity rating.
OpenCVE Enrichment