Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, contains a security misconfiguration in how it handles requests from other websites. This flaw could allow a malicious website to interact with the application on behalf of a user, potentially leading to unauthorized access to sensitive parts data or minor modifications to user information. An exploit requires a user to visit a malicious site while logged into the HCL application.
Technical details
HCL Aftermarket EPC version 1.0.0 implements a permissive Cross-Origin Resource Sharing (CORS) policy using a wildcard (*). This configuration (CWE-942) allows any third-party domain to make requests to the application and read the responses. An attacker can exploit this by enticing an authenticated user to visit a malicious website, which then uses the user's browser to perform cross-domain requests to the vulnerable HCL application. This can result in the unauthorized disclosure of sensitive information or limited data integrity impact, though the attack complexity is high as it requires specific user interaction and session timing.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: advisory: Initial NVD publication and HCL advisory release