---
id: CVE-2024-23568
title: >-
  HCL Aftermarket EPC is vulnerable to attacks since the server software version
  used by the application is revealed by the web server
summary: >-
  HCL Aftermarket EPC is vulnerable to attacks since the server software version
  used by the application is revealed by the web server. Displaying version
  information of software could allow an attacker to determine which
  vulnerabilities a…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-200
published: '2026-07-17'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-23568'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00402
epssPercentile: 0.32045
ingestedAt: '2026-10-02T01:05:54.728Z'
---

## Overview

HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
