CVE-2025-55277
Use of Vulnerable Versions in HCL Aftermarket DPC Risks Exploits
Publication date: 2026-03-26
Last updated on: 2026-03-26
Assigner: HCL Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcltech | aftermarket_cloud | 1.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1104 | The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in HCL Aftermarket DPC is due to the use of vulnerable or outdated software versions. This allows an attacker to leverage publicly available exploits from the internet to craft attacks against the application.
How can this vulnerability impact me? :
This vulnerability can potentially allow attackers to exploit known weaknesses in outdated components of the application, which may lead to limited confidentiality impact. However, the overall severity is low, with a CVSS base score of 2.6, indicating that the impact on integrity and availability is minimal.