Home

Description

HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.

PUBLISHED Reserved 2025-08-12 | Published 2026-03-26 | Updated 2026-03-26 | Assigner HCL




MEDIUM: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L

Problem types

CWE-384: Session Fixation

Product status

Default status
unaffected

version 1.0.0
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0129793

cve.org (CVE-2025-55266)

nvd.nist.gov (CVE-2025-55266)

Download JSON