CVE-2025-55272
Banner Disclosure Vulnerability in HCL Aftermarket DPC Exposes System Details
Publication date: 2026-03-26
Last updated on: 2026-03-26
Assigner: HCL Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcltech | aftermarket_cloud | 1.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
This vulnerability can impact you by revealing software and version details to attackers, which can be used to tailor attacks specifically targeting known weaknesses in those versions.
Although the CVSS base score is relatively low (3.1), indicating limited direct impact, the information disclosure can be a stepping stone for more serious attacks.
Can you explain this vulnerability to me?
The vulnerability in HCL Aftermarket DPC is a Banner Disclosure issue where attackers can obtain information about the system's software and version details.
This information disclosure allows attackers to craft attacks that are specific to the software version, potentially increasing the effectiveness of their exploits.