CVE-2024-23578

Summary

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareAftermarket EPCversion 1.0.0affected

Weaknesses

  • CWE-942: CWE-942 CWE-692: Incomplete Denial of Request to Insecure Resource

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References