CVE-2024-23578: Medium severity HCL Aftermarket EPC vulnerability
Published Jul 17, 2026
·Updated
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (-Wildcard).
Affected Software
1 affected component
HCL Aftermarket EPC
Event History
Jul 17, 2026
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-23578?
The severity of CVE-2024-23578 is rated as medium with a score of 4.2.
2
What vulnerability does CVE-2024-23578 address?
CVE-2024-23578 addresses a vulnerability in HCL Aftermarket EPC due to an improper HTML5 CORS policy allowing access from any domain.
3
How do I fix CVE-2024-23578?
To fix CVE-2024-23578, you should implement a restrictive CORS policy that limits access to trusted domains.
4
What type of vulnerability is CVE-2024-23578?
CVE-2024-23578 is a cross-origin resource sharing (CORS) vulnerability.
5
Who is affected by CVE-2024-23578?
Users of HCL Aftermarket EPC are affected by CVE-2024-23578 due to its vulnerable CORS implementation.