---
id: CVE-2024-23571
title: >-
  HCL Aftermarket EPC is vulnerable to attack since the application does not
  have an appropriate caching policy specifying the extent to which the page and
  its form fields should be cached
summary: >-
  HCL Aftermarket EPC is vulnerable to attack since the application does not
  have an appropriate caching policy specifying the extent to which the page and
  its form fields should be cached. If sensitive information in application
  responses…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-525
published: '2026-07-17'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-23571'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00297
epssPercentile: 0.20211
ingestedAt: '2026-10-02T01:05:54.730Z'
---

## Overview

HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
