7.5
CVE-2025-55265
- EPSS 0.01%
- Veröffentlicht 26.03.2026 13:02:42
- Zuletzt bearbeitet 26.03.2026 20:16:44
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
HCL Aftermarket DPC is affected by File Discovery
HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and may use it to craft further attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Aftermarket Cloud Version1.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.026 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| psirt@hcl.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.