Technology · HCL Software
HCL Software Aftermarket EPC vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in HCL Software Aftermarket EPC: 0 in the last 7 days and 15 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2024-42214, was published on 17 July 2026.
- Last 7 days
- 0
- Last 90 days
- 15
- Critical, all time
- 1
- Exploited in the wild
- 0
About HCL Software Aftermarket EPC
An electronic parts catalog application used for managing and distributing automotive and industrial parts information.
Latest HCL Software Aftermarket EPC vulnerabilities
- CVE-2024-42214: HCL Aftermarket EPC information disclosure via HTTP OPTIONS methodmediumCVSS 5.3
- CVE-2024-23578: HCL Aftermarket EPC permissive CORS policymediumCVSS 4.2
- CVE-2024-23577: HCL Aftermarket EPC Host header poisoningmediumCVSS 4.3
- CVE-2024-23575: HCL Aftermarket EPC information disclosure via detailed error messagesmediumCVSS 5.3
- CVE-2024-23574: HCL Aftermarket EPC user enumeration via response discrepancymediumCVSS 5.3
- CVE-2024-23573: HCL Aftermarket EPC Lucky 13 timing attack in TLS/DTLSlowCVSS 3.7
- CVE-2024-23572: HCL Aftermarket EPC insecure session cookie attributesmediumCVSS 4.2
- CVE-2024-23571: HCL Aftermarket EPC improper caching policy in web interfacemediumCVSS 4.3
- CVE-2024-23570: HCL Aftermarket EPC clickjacking vulnerabilitymediumCVSS 4.3
- CVE-2024-23569: HCL Aftermarket EPC missing X-XSS-Protection headermediumCVSS 4.3
- CVE-2024-23568: HCL Aftermarket EPC information disclosure via server version leakagemediumCVSS 5.3
- CVE-2024-23567: HCL Aftermarket EPC sensitive information exposure in URL parametersmediumCVSS 4.3
- CVE-2024-23566: HCL Aftermarket EPC brute force vulnerability due to missing CAPTCHAmediumCVSS 6.5
- CVE-2024-23565: HCL Aftermarket EPC email flooding in Forgot Password functionalitymediumCVSS 5.3
- CVE-2024-23564: HCL Aftermarket EPC business logic vulnerability in password recoverycriticalCVSS 9.1
Most severe HCL Software Aftermarket EPC vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-23564: HCL Aftermarket EPC business logic vulnerability in password recoverycriticalCVSS 9.1
- CVE-2024-23566: HCL Aftermarket EPC brute force vulnerability due to missing CAPTCHAmediumCVSS 6.5
- CVE-2024-42214: HCL Aftermarket EPC information disclosure via HTTP OPTIONS methodmediumCVSS 5.3
- CVE-2024-23575: HCL Aftermarket EPC information disclosure via detailed error messagesmediumCVSS 5.3
- CVE-2024-23574: HCL Aftermarket EPC user enumeration via response discrepancymediumCVSS 5.3
- CVE-2024-23568: HCL Aftermarket EPC information disclosure via server version leakagemediumCVSS 5.3
- CVE-2024-23565: HCL Aftermarket EPC email flooding in Forgot Password functionalitymediumCVSS 5.3
- CVE-2024-23577: HCL Aftermarket EPC Host header poisoningmediumCVSS 4.3
- CVE-2024-23571: HCL Aftermarket EPC improper caching policy in web interfacemediumCVSS 4.3
- CVE-2024-23570: HCL Aftermarket EPC clickjacking vulnerabilitymediumCVSS 4.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 15 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/aftermarket-epc.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "HCL Software Aftermarket EPC vulnerabilities", https://junglewise.ai/threats/technologies/aftermarket-epc, 26 September 2026.