CVE-2024-42214

⚪ Do wiadomości

Włączenie metody HTTP OPTIONS w HCL Aftermarket EPC umożliwia atakującym zbieranie informacji o serwerze.

CVSS
5.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-07-17 14:17:18 UTC
Ostatnia modyfikacja (NVD)2026-10-02 00:10:00 UTC
Referencje