CVE-2024-23572

Summary

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareAftermarket EPCversion 1.0.0affected

Weaknesses

  • CWE-614: CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References