Executive brief
HCL iControl version 4.0.0 is affected by a vulnerability that can reveal internal technical details about the application's software structure. When the system encounters a specific error, it displays a detailed stack trace instead of a generic error message. An attacker could use this information to better understand the system's internal workings, potentially aiding in the development of more sophisticated attacks.
Technical details
HCL iControl v4.0.0 contains a CWE-209 vulnerability where the application generates error messages containing sensitive information. The issue occurs in the application's JavaScript code when an undefined property (specifically a 'dashboard key') is accessed on an uninitialized or missing object. This triggers an unhandled exception that discloses a stack trace to the user. An authenticated attacker with network access can trigger this condition to gain insights into the application's internal logic and environment. The vulnerability has a low CVSS score (3.1) due to the high complexity required to leverage this information and the limited impact on confidentiality.
Affected products
- HCL iControl 4.0.0
Timeline
- 2026-06-04: advisory: NVD and HCL published the vulnerability details.