Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is configured with the HTTP OPTIONS method enabled. This allows potential attackers to easily discover which communication methods the server supports, such as those that might allow data modification or deletion. While not a direct breach itself, this information helps attackers plan more sophisticated and targeted attacks against the system.
Technical details
HCL Aftermarket EPC version 1.0.0 is susceptible to information disclosure due to the web server's configuration allowing the HTTP OPTIONS method. By sending an OPTIONS request, an unauthenticated remote attacker can retrieve a list of all supported HTTP methods (e.g., POST, PUT, DELETE) available on the server. This reconnaissance capability allows an attacker to identify potentially dangerous methods that may be improperly secured, facilitating further exploitation. The vulnerability is classified under CWE-692 and carries a CVSS score of 5.3, reflecting a low-impact information leak.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: advisory: Initial disclosure by HCL Software and NVD publication.