Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is susceptible to information leakage through its error handling. The application provides overly detailed error messages that reveal internal server processing details to any user on the network. While this does not directly grant access to data, an attacker can use this technical information to map out the system and plan more sophisticated, targeted attacks against the organization.
Technical details
HCL Aftermarket EPC version 1.0.0 is vulnerable to CWE-209 (Generation of Error Message Containing Sensitive Information). The application's error handling logic returns verbose technical details about server-side processing directly to the client. This vulnerability is reachable over the network without authentication. An attacker can trigger various error conditions to gather reconnaissance data regarding the underlying infrastructure, software versions, or code logic, which can be leveraged to identify further exploitable vulnerabilities. Users are advised to consult HCL Software advisory KB0132294 for remediation steps.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: disclosed: Initial publication of the CVE record.
- 2026-07-17: advisory: HCL Software released security bulletin KB0132294.