Junglewise Threat Intelligence

CVE-2024-23571: HCL Aftermarket EPC improper caching policy in web interface

CVE-2024-23571 · Severity: medium · CVSS 4.3 · Published 2026-07-17

Technologies: HCL Software Aftermarket EPC. Vendors: HCL Software.

Executive brief

HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, fails to properly instruct web browsers on how to handle sensitive data in their local cache. This could allow an unauthorized person with physical or shared access to a computer to view sensitive information or form data previously entered by a legitimate user. This poses a risk to data privacy, particularly on shared workstations or public computers.

Technical details

HCL Aftermarket EPC version 1.0.0 is vulnerable to CWE-525 (Use of Web Browser Cache Containing Sensitive Information). The application lacks appropriate Cache-Control or Pragma HTTP headers, leading to the storage of sensitive application responses and form data in the local browser cache. An attacker with access to the same local machine or browser profile used by a victim can retrieve this cached information after the session has ended. While the attack vector is classified as network-based in the CVSS string, the practical exploitation requires subsequent local access to the user's environment.

Affected products

  • HCL Software Aftermarket EPC 1.0.0

Timeline

  • 2026-07-17: advisory: Initial advisory published by HCL Software and NVD.

References

Related threats