Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, contains a security flaw in how it handles user session cookies. Because these cookies are not properly secured, an attacker could potentially intercept them during a user's session. If successful, this could allow an unauthorized person to gain limited access to the application or monitor user activity.
Technical details
HCL Aftermarket EPC version 1.0.0 is vulnerable to a sensitive cookie exposure flaw (CWE-614). The application fails to properly configure security attributes, such as the 'Secure' flag, on cookies that appear to contain session tokens. This vulnerability typically allows an attacker to intercept session identifiers over unencrypted channels or via man-in-the-middle (MITM) attacks. Exploitation requires network access and specific conditions (high attack complexity) such as a user being tricked into a specific interaction or an insecure network environment. The impact is a partial loss of confidentiality and integrity.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: advisory: Initial advisory published by HCL Software and NVD