CVE-2024-42214

Summary

HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareAftermarket EPCversion 1.0.0affected

Weaknesses

  • CWE-692: CWE-692: Incomplete Denial of Request to Insecure Resource

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References