CVE-2023-37516
CVSS 3.1 Score 3.2 of 10 (low)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 524
Summary
CVE-2023-37516 is a vulnerability affecting HCL Leap. The issue arises due to the absence of "no cache" headers, allowing user directory information to be cached. As a result, an attacker may gain unauthorized access to sensitive information by exploiting this cache. Organizations using HCL Leap are advised to implement proper caching controls to mitigate this risk and prevent potential data breaches. Failure to address this vulnerability could lead to exposure of user directories, threatening the confidentiality and integrity of the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- HCL Leap
Affected Vendors
- HCL Software