SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-23572

MEDIUM · CVSS 4.2 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

HCL Aftermarket EPC is vulnerable due to the presence of a session token within its cookies, potentially exposing sensitive session information to unauthorized access. This could lead to session hijacking or unauthorized actions within the application. Organizations using HCL Aftermarket EPC should prioritize reviewing and securing cookie contents to mitigate the associated risks.

CVE
CVE-2024-23572
Severity
MEDIUM
CVSS
4.2
EPSS
0.09%

Original NVD Description

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.