Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, contains a security flaw that allows unauthorized individuals to steal user passwords. By manipulating how the server responds to requests, an attacker can trick the system into sending account passwords to an email address of their choosing. This could lead to full account takeovers and unauthorized access to sensitive business data.
Technical details
A business logic vulnerability exists in HCL Aftermarket EPC version 1.0.0. While the application validates the 'UserId' during initial authentication requests, it fails to perform similar validation during subsequent email-based password recovery or transmission requests. An unauthenticated remote attacker can exploit this by manipulating server responses to redirect password-containing emails to an arbitrary address. This bypasses intended access controls, leading to the disclosure of cleartext or recoverable credentials. The vulnerability is tracked as CVE-2024-23564 and has been assigned a CVSS score of 9.1.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory