MEDIUM🇬🇧 English

CVE-2024-42214

CVSS 5.3v3.1pub. 2026-07-17

HCL Aftermarket EPC jest podatny na ataki, ponieważ metoda HTTP OPTIONS jest włączona na serwerze. Metoda OPTIONS udostępnia listę metod obsługiwanych przez serwer, co pozwala atakującemu zawęzić i wzmocnić swoje działania.

Pokaż oryginał (EN)

HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje