CVE-2024-23564 -- CVSS 9.1 Vulnerability Briefing
CVE-2024-23564 | CVSS 9.1 (Critical) | Exploit: No known exploit
What Is It
CVE-2024-23564 is a critical business logic vulnerability in HCL Aftermarket EPC that may allow an unauthenticated, invalid application user to obtain passwords from the server and redirect them to an attacker-controlled email address.
Technical Detail
The vulnerability affects password-related application logic in HCL Aftermarket EPC. An attacker may be able to abuse the affected workflow without valid authorization to retrieve passwords from the server and cause them to be sent to an email address under the attacker’s control. Successful exploitation could enable unauthorized account access and compromise of accounts whose passwords are exposed through the vulnerable process.
Exploitation Status
No known public exploit or confirmed exploitation in the wild has been reported as of July 24, 2026. This CVE is not listed in CISA's Known Exploited Vulnerabilities Catalog.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize applying the vendor-provided remediation for HCL Aftermarket EPC after validating compatibility in a controlled environment. Review password-reset, password-retrieval, and email-redirection workflows to ensure they require strong authentication and cannot disclose passwords or direct sensitive messages to unverified email addresses. Review application and mail-delivery logs for password-related requests associated with unknown accounts, unusual recipient email addresses, repeated failed authentication attempts, or unexpected password delivery activity. Reset potentially exposed credentials, require users to establish new passwords where exposure is suspected, and enforce multifactor authentication where available. No vendor workaround or specific detection signature is confirmed in the available CVE data.