CVE-2025-55266
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.
Affected (1)
Products: Hcltech: Aftermarket Cloud
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0 |
References (1)
Source: psirt@hcl.com
Vendor Advisory
Timeline
No history available yet.