Impact
The vulnerability is a low‑severity input reflection flaw in HCL Traveler’s Apple profile generation. When users create a profile, the system requires them to provide a Logon Name and Mail Address and then reflects those values back into the generated profile without modification. The flaw allows the authenticated user to capture their own credentials in the profile, but the data cannot be altered later and the feature cannot be abused to affect other devices or users. The weakness maps to input validation and mishandling of user data (CWE‑20, CWE‑184).
Affected Systems
The flaw affects HCL Traveler from HCLSoftware. No specific product versions are listed in the available data.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local; an attacker must be authenticated to the Traveler system in order to request an Apple profile. This limits exploitation to the user’s own device, confining impact to potential information disclosure of their login credentials and the system’s Apple profile content.
OpenCVE Enrichment