HomeCVE Intelligence › CVE-2024-23564
CVSS 9.1 CRITICAL Vulnerability

CVE-2024-23564: CVE-2024-23564 - HCL Aftermarket EPC Business Logic Vulnerability

CVE ID : CVE-2024-23564 Published : July 17, 2026, 1:25 p.m. | 4minutes ago Description : HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwo…

9.1CVSS Score
CRITICALSeverity
NOCISA KEV
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2024-23564
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeVulnerability
CVSS Score9.1 (CRITICAL)
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

CVE ID : CVE-2024-23564

Published : July 17, 2026, 1:25 p.m. | 4minutes ago

Description : HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests wh

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2024-23564","confidence_score":23.5,"first_seen":"2026-07-17","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2024-23564 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence