CVE-2024-23578: Hclsoftware Aftermarket Epc

Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).

Affected products

Published 2026-07-17. Last modified 2026-10-02.