CVE-2024-23564: Weak Encryption
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23564?
CVE-2024-23564 has a critical severity rating of 9.1.
How do I fix CVE-2024-23564?
To fix CVE-2024-23564, apply the latest security patch provided by HCL for the Aftermarket EPC software.
What impact does CVE-2024-23564 have on users?
CVE-2024-23564 allows non-valid users to obtain passwords from the server, leading to potential unauthorized access.
Is CVE-2024-23564 being actively exploited?
There are no public reports of active exploitation of CVE-2024-23564 at this time.
What types of vulnerabilities are associated with CVE-2024-23564?
CVE-2024-23564 is associated with a business logic vulnerability and weak encryption.