3.2 CVE-2023-37516

 

Missing "no cache" headers in HCL Leap permits user directory information to be cached.
https://nvd.nist.gov/vuln/detail/CVE-2023-37516

Categories

CWE-524 : Use of Cache Containing Sensitive Information
Applications may use caches to improve efficiency when communicating with remote entities or performing intensive calculations. A cache maintains a pool of objects, threads, connections, pages, financial data, passwords, or other resources to minimize the time it takes to initialize and access these resources. If the cache is accessible to unauthorized actors, attackers can read the cache and obtain this sensitive information.

References


 

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
204 Lifting Sensitive Data Embedded in Cache
Medium


MITRE


Techniques

id description
T1005 Data from Local System
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Mitigations

id description
M1057 Data loss prevention can restrict access to sensitive data and detect sensitive data that is unencrypted.
© 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation.