Admin Session Concurrency Vulnerability in HCL Aftermarket DPC
CVE-2025-55275

3.7LOW

Key Information:

Vendor
CVE Published:
26 March 2026

What is CVE-2025-55275?

The HCL Aftermarket DPC product is susceptible to an Admin Session Concurrency vulnerability, which allows attackers to exploit concurrent sessions. This can lead to unauthorized access where an attacker could hijack or impersonate an administrative user, potentially compromising critical system operations and sensitive data.

Affected Version(s)

Aftermarket DPC version 1.0.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.