← Vulnerability feed

Vulnerability record · CVE-2025-55275 · published 26 March 2026

CVE-2025-55275: Hcltech aftermarket cloud vulnerability

Hcltech · Aftermarket Cloud

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user.

8.1 CVSS 3.1 High EPSS 0.22% · top 89.0% CWE-557 · CWE-557
8.1CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-55275 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-55261Hcltech aftermarket cloud improper access control vulnerabilityHCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th…EPSS 0.32%9.8CVE-2025-55269Hcltech aftermarket cloud weak password requirements vulnerabilityHCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force…EPSS 0.24%9.8CVE-2025-55270Hcltech aftermarket cloud improper input validation vulnerabilityHCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS…EPSS 1.00%9.8CVE-2025-55267Hcltech aftermarket cloud unrestricted file upload vulnerabilityHCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full cont…EPSS 0.30%8.8CVE-2025-55271Hcltech aftermarket cloud vulnerabilityHCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an…EPSS 0.32%7.5CVE-2025-55263Hcltech aftermarket cloud hard-coded credentials vulnerabilityHCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure re…EPSS 0.19%7.5CVE-2025-55262Hcltech aftermarket cloud hard-coded credentials vulnerabilityHCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab…EPSS 0.27%7.5CVE-2025-55265Hcltech aftermarket cloud information exposure vulnerabilityHCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and ma…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2025-55275), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.