HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-31 16:17
Updated : 2026-08-06 14:46
NVD link : CVE-2026-56568
Mitre link : CVE-2026-56568
CVE.ORG link : CVE-2026-56568
JSON object : View
Products Affected
hcltech
- icontrol
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
