CVE-2025-55266

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/03/2026
Last modified:
26/03/2026

Description

HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:aftermarket_cloud:1.0.0:*:*:*:*:*:*:*