Junglewise Threat Intelligence

CVE-2024-23577: HCL Aftermarket EPC Host header poisoning

CVE-2024-23577 · Severity: medium · CVSS 4.3 · Published 2026-07-17

Technologies: HCL Software Aftermarket EPC. Vendors: HCL Software.

Executive brief

HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is vulnerable to a security flaw where it fails to verify the identity of the server requested by a user. An attacker could exploit this to redirect users to malicious websites or interfere with how the application communicates, potentially leading to the theft of sensitive information or unauthorized access to user sessions. This issue primarily affects systems using the standard HTTP protocol without proper header validation.

Technical details

HCL Aftermarket EPC version 1.0.0 is vulnerable to Host header poisoning due to improper input validation (CWE-20) of the HTTP Host header. The application accepts arbitrary hostnames provided in the header when communicating via the HTTP protocol. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the server. Successful exploitation can lead to various attacks, including web cache poisoning, password reset poisoning, or bypassing security controls that rely on the Host header for routing or domain-specific logic. The vulnerability is confirmed in version 1.0.0.

Affected products

  • HCL Software Aftermarket EPC 1.0.0

Timeline

  • 2026-07-17: advisory: NVD and HCL published the vulnerability details.

References

Related threats