Fiche vulnérabilité
CVE-2025-55266 : faille moyenne hcltech aftermarket cloud (CVSS 6.5)
Description
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.
En bref
- Sévérité
- Moyenne (CVSS 6.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 26 mars 2026
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- hcltech aftermarket cloud