Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is leaking its internal server software version information to the public internet. While this does not directly grant access to data, it provides attackers with a roadmap of the system's specific technologies and potential weaknesses. This information significantly simplifies the process for a malicious actor to identify and launch targeted attacks against the infrastructure.
Technical details
HCL Aftermarket EPC version 1.0.0 is affected by an information exposure vulnerability (CWE-200) where the web server reveals its software version in HTTP response headers or error pages. This is a passive reconnaissance vulnerability reachable over the network without authentication. By identifying the exact version of the underlying server software, an attacker can cross-reference known CVEs for that specific version to facilitate further exploitation. The vulnerability is addressed in HCL's security bulletin KB0132294.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: advisory: NVD publication date