CVE-2024-23565: Medium severity HCL Aftermarket EPC vulnerability
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23565?
The severity of CVE-2024-23565 is classified as medium with a score of 5.3.
How do I fix CVE-2024-23565?
To mitigate CVE-2024-23565, implement a mail limitation mechanism for the Forget Password functionality.
What is the impact of CVE-2024-23565?
CVE-2024-23565 can lead to email flooding, potentially causing a denial of service.
Which software is affected by CVE-2024-23565?
CVE-2024-23565 affects the HCL Aftermarket EPC software.
What is the nature of the attack vector for CVE-2024-23565?
The attack vector for CVE-2024-23565 can be executed by either a human actor or an automated process like a bot or virus.