← Zuruck zu CVEs
CVE-2025-55266
MEDIUM5.9
Beschreibung
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.
CVE Details
CVSS v3.1 Bewertung5.9
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L
AngriffsvektorNETWORK
KomplexitatHIGH
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht3/26/2026
Zuletzt geandert3/26/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
hcltech:aftermarket_cloud
Schwachen (CWE)
CWE-384
Referenzen
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.