CVE-2024-23567: Medium severity HCL Aftermarket EPC vulnerability
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23567?
The severity of CVE-2024-23567 is rated medium with a base score of 4.3.
How do I fix CVE-2024-23567?
To fix CVE-2024-23567, ensure that sensitive information is not passed in GET requests or URL parameters.
What type of data is affected by CVE-2024-23567?
CVE-2024-23567 affects sensitive information that may be included in URL parameters during normal application usage.
What impact does CVE-2024-23567 have on data security?
CVE-2024-23567 can lead to exposure of sensitive data as it may be logged or stored in unintended locations.
Which software is impacted by CVE-2024-23567?
CVE-2024-23567 affects the HCL Aftermarket EPC software.