Impact
HCL Aftermarket EPC has a business‑logic flaw that allows a non‑valid user to trigger a password recovery operation. Because the email‑recovery endpoint lacks proper validation that is applied to the initial UserId checks, attackers can cause the server to send user passwords to an arbitrary e‑mail address, exposing credentials without authorization. This weakness is a weak password handling flaw (CWE-326).
Affected Systems
HCL Software’s Aftermarket EPC product is the affected system; no specific versions are listed in the available data.
Risk and Exploitability
The CVSS score of 9.1 classifies this issue as a high‑severity vulnerability. The EPSS score is below 1 percent, indicating a low likelihood of exploitation at present. It does not appear in the CISA KEV catalog, suggesting that no known public exploits exist. Attackers can exploit the vulnerability by accessing the email‑recovery endpoint without proper authentication or by supplying a non‑existent user identifier, thereby manipulating the server to send passwords to an arbitrary e‑mail address. This vulnerability arises from a weak password handling flaw (CWE-326).
OpenCVE Enrichment