SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-23571

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

HCL Aftermarket EPC is vulnerable due to an inadequate caching policy, which may allow sensitive information from application responses to be stored in the local cache. This could lead to unauthorized access to sensitive data by other users on the same device. Organizations using this application should prioritize addressing this vulnerability to mitigate the risk of data exposure.

CVE
CVE-2024-23571
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.