CyberRota Analysis
AI-GeneratedHCL iControl is vulnerable due to its exposure of verbose client-side API error messages, which reveal sensitive information such as internal endpoint names, request parameters, error codes, and authentication status. This information leakage could aid attackers in crafting targeted exploits against the application. Organizations using HCL iControl should prioritize addressing this vulnerability to mitigate potential risks associated with information exposure.
Original NVD Description
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status
Related CVEs
Other vulnerabilities affecting the same vendor(s)