Medium severity5.9NVD Advisory· Published Mar 26, 2026· Updated Jun 17, 2026
CVE-2025-55266
CVE-2025-55266
Description
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: version 1.0.0
- cpe:2.3:a:hcltech:aftermarket_cloud:1.0.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- support.hcl-software.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.