Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, fails to properly instruct web browsers on how to handle sensitive data in their local cache. This could allow an unauthorized person with physical or shared access to a computer to view sensitive information or form data previously entered by a legitimate user. This poses a risk to data privacy, particularly on shared workstations or public computers.
Technical details
HCL Aftermarket EPC version 1.0.0 is vulnerable to CWE-525 (Use of Web Browser Cache Containing Sensitive Information). The application lacks appropriate Cache-Control or Pragma HTTP headers, leading to the storage of sensitive application responses and form data in the local browser cache. An attacker with access to the same local machine or browser profile used by a victim can retrieve this cached information after the session has ended. While the attack vector is classified as network-based in the CVSS string, the practical exploitation requires subsequent local access to the user's environment.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: advisory: Initial advisory published by HCL Software and NVD.