« Volver al listado

CVE-2025-0279

Estado: AnalizadaMedia (4.3)—

HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-0279",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-0279",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-07T16:31:42.795955Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@hcl.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@hcl.com",
      "affectedData": [
        {
          "vendor": "HCL Software",
          "product": "HCL Traveler",
          "versions": [
            {
              "status": "affected",
              "version": "<=14.0.0.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-04-03T22:15:16.700",
  "references": [
    {
      "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120336",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@hcl.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@hcl.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-209"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.  Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks."
    },
    {
      "lang": "es",
      "value": "HCL Traveler genera mensajes de error que proporcionan información detallada sobre errores y fallos, como rutas internas, nombres de archivo, tokens confidenciales, credenciales, códigos de error o seguimientos de pila. Los atacantes podrían explotar esta información para obtener información sobre la arquitectura del sistema y, potencialmente, lanzar ataques dirigidos."
    }
  ],
  "lastModified": "2026-06-17T08:26:12.173",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hcltech:traveler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88054BA7-F9D1-41E4-AEA8-D362CEB4A4CC",
              "versionEndIncluding": "14.0.0.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@hcl.com"
}