CVE-2024-23568: Infoleak
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disable or otherwise prevent the web server from disclosing the HCL Aftermarket EPC server software version (e.g., remove/version-banner headers and any page/UI elements that reveal server version).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23568?
The severity of CVE-2024-23568 is medium with a score of 5.3.
What vulnerabilities does CVE-2024-23568 expose?
CVE-2024-23568 exposes the application to potential attacks due to server software version information being revealed.
How can I mitigate CVE-2024-23568?
To mitigate CVE-2024-23568, ensure that server software version information is not disclosed to users.
What software is affected by CVE-2024-23568?
CVE-2024-23568 affects the HCL Aftermarket EPC application.
When was CVE-2024-23568 published?
CVE-2024-23568 was published on July 17, 2026.