ZeroHour

CVE-2025-55266

CVSS 3.1
6.5 medium
EPSS
<1%p16
Published
()
Modified
Description

HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.

Vendors
hcltech
Products
aftermarket cloud
Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.