Impact
HCL Aftermarket EPC fails to enforce an appropriate caching policy, allowing pages that include sensitive information to be cached locally. If such responses are stored in the browser or local cache, another user who has access to the same device can retrieve that information at a later time. This flaw is an example of CWE‑525, where cached data may be accessed by unintended parties. The primary consequence is a confidentiality breach, with no impact on integrity or availability reported.
Affected Systems
The vulnerability applies to HCLSoftware's Aftermarket EPC application. No specific version range is referenced in the advisory, so all current releases are potentially affected until a patch is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be local: an attacker must have physical or shared access to a device that has cached the affected page. Under those conditions, the vulnerable application could expose confidential data to other users of the same computer.
OpenCVE Enrichment