---
id: CVE-2024-23567
title: >-
  HCL Aftermarket EPC is affected by Sensitive Information in GET method & in
  URL which allows application to pass sensitive data via URL parameters during
  normal usage
summary: >-
  HCL Aftermarket EPC is affected by Sensitive Information in GET method & in
  URL which allows application to pass sensitive data via URL parameters during
  normal usage. Data passed in this manner can be exposed because it may end up
  store…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-804
published: '2026-07-17'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-23567'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00306
epssPercentile: 0.2114
ingestedAt: '2026-10-02T01:05:54.728Z'
---

## Overview

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
