---
id: CVE-2024-23575
title: >-
  HCL Aftermarket EPC is vulnerable to attack since the application returns
  detailed error messages that leak information about the processing on the
  server
summary: >-
  HCL Aftermarket EPC is vulnerable to attack since the application returns
  detailed error messages that leak information about the processing on the
  server. An attacker may use the contents of error messages to help launch
  another ,more f…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-209
published: '2026-07-17'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-23575'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.0033
epssPercentile: 0.23722
ingestedAt: '2026-10-02T01:05:54.731Z'
---

## Overview

HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
