CVE-2023-37516: HCL Leap is affected by missing "no cache" headers
Published Apr 24, 2025
·Updated
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
Affected Software
2 affected components
HCL Leap
hcltech Hcl Leap<9.3.4
Event History
Apr 24, 2025
CVE Published
via MITRE·08:37 PM
Data Sourced
via MITRE·08:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37516?
CVE-2023-37516 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-37516?
To fix CVE-2023-37516, configure HCL Leap to include appropriate 'no cache' headers in the user directory responses.
3
What systems are affected by CVE-2023-37516?
CVE-2023-37516 affects HCL Leap software.
4
What are the potential impacts of CVE-2023-37516?
The potential impact of CVE-2023-37516 includes unauthorized caching of user directory information.
5
Is there a patch available for CVE-2023-37516?
Yes, it is recommended to check HCL's support resources for updates or patches addressing CVE-2023-37516.