CVE-2024-23575

MEDIUM

Hclsoftware Aftermarket Epc - Generation of Error Message Containing Sensitive Information

Title source: rule
STIX 2.1

Description

HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.

Scores

CVSS v3 5.3
EPSS 0.0020
EPSS Percentile 9.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
HCLSoftware/Aftermarket EPC version 1.0.0
Published Jul 17, 2026
Tracked Since Jul 17, 2026