Junglewise Threat Intelligence

CVE-2024-42214: HCL Aftermarket EPC information disclosure via HTTP OPTIONS method

CVE-2024-42214 · Severity: medium · CVSS 5.3 · Published 2026-07-17

Technologies: HCL Software Aftermarket EPC. Vendors: HCL Software.

Executive brief

HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is configured with the HTTP OPTIONS method enabled. This allows potential attackers to easily discover which communication methods the server supports, such as those that might allow data modification or deletion. While not a direct breach itself, this information helps attackers plan more sophisticated and targeted attacks against the system.

Technical details

HCL Aftermarket EPC version 1.0.0 is susceptible to information disclosure due to the web server's configuration allowing the HTTP OPTIONS method. By sending an OPTIONS request, an unauthenticated remote attacker can retrieve a list of all supported HTTP methods (e.g., POST, PUT, DELETE) available on the server. This reconnaissance capability allows an attacker to identify potentially dangerous methods that may be improperly secured, facilitating further exploitation. The vulnerability is classified under CWE-692 and carries a CVSS score of 5.3, reflecting a low-impact information leak.

Affected products

  • HCL Software Aftermarket EPC 1.0.0

Timeline

  • 2026-07-17: advisory: Initial disclosure by HCL Software and NVD publication.

References

Related threats