Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2024-23564 -- CVSS 9.1 Vulnerability Briefing

CVE-2024-23564 | CVSS 9.1 (Critical) | Exploit: No known exploit

What Is It

CVE-2024-23564 is a critical business logic vulnerability in HCL Aftermarket EPC that may allow an unauthenticated, invalid application user to obtain passwords from the server and redirect them to an attacker-controlled email address.

Technical Detail

The vulnerability affects password-related application logic in HCL Aftermarket EPC. An attacker may be able to abuse the affected workflow without valid authorization to retrieve passwords from the server and cause them to be sent to an email address under the attacker’s control. Successful exploitation could enable unauthorized account access and compromise of accounts whose passwords are exposed through the vulnerable process.

Exploitation Status

No known public exploit or confirmed exploitation in the wild has been reported as of July 24, 2026. This CVE is not listed in CISA's Known Exploited Vulnerabilities Catalog.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize applying the vendor-provided remediation for HCL Aftermarket EPC after validating compatibility in a controlled environment. Review password-reset, password-retrieval, and email-redirection workflows to ensure they require strong authentication and cannot disclose passwords or direct sensitive messages to unverified email addresses. Review application and mail-delivery logs for password-related requests associated with unknown accounts, unusual recipient email addresses, repeated failed authentication attempts, or unexpected password delivery activity. Reset potentially exposed credentials, require users to establish new passwords where exposure is suspected, and enforce multifactor authentication where available. No vendor workaround or specific detection signature is confirmed in the available CVE data.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →