HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.  Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 10 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Hcltech Hcltech traveler | |
| CPEs | cpe:2.3:a:hcltech:traveler:*:*:*:*:*:*:*:* | |
| Vendors & Products | Hcltech Hcltech traveler | 
Mon, 07 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 03 Apr 2025 22:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks. | |
| Title | HCL Traveler is affected by generation of error messages containing sensitive information | |
| Weaknesses | CWE-209 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: HCL
Published: 2025-04-03T21:48:01.004Z
Updated: 2025-04-07T16:31:57.411Z
Reserved: 2025-01-06T16:01:36.580Z
Link: CVE-2025-0279
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-07T16:31:50.571Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-04-03T22:15:16.700
Modified: 2025-10-10T16:47:02.997
Link: CVE-2025-0279
 Redhat
                        Redhat
                    No data.