Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is vulnerable to automated login attacks. Because the application lacks rate-limiting or CAPTCHA protections, unauthorized individuals can use automated tools to guess user passwords or identify valid account names. This could lead to unauthorized access to the system, potential data theft, or disruption of parts management operations.
Technical details
HCL Aftermarket EPC version 1.0.0 is vulnerable to brute force attacks and account enumeration. The vulnerability stems from a lack of anti-automation mechanisms, such as CAPTCHA or account lockout policies, on authentication endpoints. A remote, unauthenticated attacker can leverage this to perform high-velocity automated login attempts to guess credentials or verify the existence of user accounts. Successful exploitation can lead to unauthorized access to the application. Users are advised to refer to HCL Software security bulletin KB0132294 for remediation steps.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: advisory: NVD and HCL Software published the vulnerability details.