Filtered by vendor Hclsoftware Subscriptions
Filtered by product Aftermarket Epc Subscriptions
Total 6 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-23574 1 Hclsoftware 1 Aftermarket Epc 2026-07-23 5.3 Medium
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
CVE-2024-23577 1 Hclsoftware 1 Aftermarket Epc 2026-07-23 4.3 Medium
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server misconfigurations.
CVE-2024-23569 1 Hclsoftware 1 Aftermarket Epc 2026-07-23 4.3 Medium
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23578 1 Hclsoftware 1 Aftermarket Epc 2026-07-23 4.2 Medium
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
CVE-2024-23570 1 Hclsoftware 1 Aftermarket Epc 2026-07-23 4.3 Medium
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.
CVE-2024-23572 1 Hclsoftware 1 Aftermarket Epc 2026-07-23 4.2 Medium
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.