Aftermarket EPC
by HCL Software
CVEs (15)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-23572 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function. | |||
| CVE-2024-23570 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing,… | |||
| CVE-2024-23578 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard). | |||
| CVE-2024-23569 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header | |||
| CVE-2024-23577 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks,… | |||
| CVE-2024-23574 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid… | |||
| CVE-2024-42214 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts. | |||
| CVE-2024-23575 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack. | |||
| CVE-2024-23571 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this… | |||
| CVE-2024-23573 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be… | |||
| CVE-2024-23568 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly… | |||
| CVE-2024-23565 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service,… | |||
| CVE-2024-23566 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration | |||
| CVE-2024-23567 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including… | |||
| CVE-2024-23564 | 0.00 | — | 0.00 | Jul 17, 2026 | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial… |
- CVE-2024-23572Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.
- CVE-2024-23570Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing,…
- CVE-2024-23578Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
- CVE-2024-23569Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
- CVE-2024-23577Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks,…
- CVE-2024-23574Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid…
- CVE-2024-42214Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.
- CVE-2024-23575Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.
- CVE-2024-23571Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this…
- CVE-2024-23573Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be…
- CVE-2024-23568Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly…
- CVE-2024-23565Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service,…
- CVE-2024-23566Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
- CVE-2024-23567Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including…
- CVE-2024-23564Jul 17, 2026risk 0.00cvss —epss 0.00
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial…