{"success":true,"data":{"threats":[{"id":"ad760041-73f2-4b7e-99ad-50c79113de43","slug":"cve-2024-42214","externalId":"CVE-2024-42214","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2024-42214 — HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.","description":"HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.","cveId":"CVE-2024-42214","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-692"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294","type":"advisory","title":"psirt@hcl.com"}],"epssScore":0.0033,"epssPercentile":0.24068,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-17T14:17:18.863Z","addedAt":"2026-10-02T01:50:40.968Z","updatedAt":"2026-10-02T01:50:40.968Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42214","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2024-42214","note":"authoritative record"}],"raw":{"id":"CVE-2024-42214","cveTags":[],"metrics":{"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2024-42214","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"version":"2.0.3","timestamp":"2026-07-17T15:20:04.055235Z"}}],"cvssMetricV31":[{"type":"Secondary","source":"psirt@hcl.com","cvssData":{"scope":"UNCHANGED","version":"3.1","baseScore":5.3,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"NONE","confidentialityImpact":"LOW"},"impactScore":1.4,"exploitabilityScore":3.9}]},"affected":[{"source":"psirt@hcl.com","affectedData":[{"vendor":"HCLSoftware","product":"Aftermarket EPC","versions":[{"status":"affected","version":"version 1.0.0"}],"defaultStatus":"unaffected"}]}],"published":"2026-07-17T14:17:18.863","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294","source":"psirt@hcl.com"}],"vulnStatus":"Deferred","weaknesses":[{"type":"Secondary","source":"psirt@hcl.com","description":[{"lang":"en","value":"CWE-692"}]}],"descriptions":[{"lang":"en","value":"HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts."},{"lang":"es","value":"HCL Aftermarket EPC es vulnerable a ataques ya que el método HTTP OPTIONS está habilitado en este servidor web. El método OPTIONS proporciona una lista de los métodos que son compatibles con el servidor web, lo que permite a un atacante reducir e intensificar sus esfuerzos."}],"lastModified":"2026-10-02T00:10:00.180","sourceIdentifier":"psirt@hcl.com"}}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:50:12.253Z","durationMs":8,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":"CVE-2024-42214","source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":["include"],"warnings":[]}}