Description
HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate the data.
CVSS Metrics
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
- Attack Vector
- network
- Complexity
- low
- Privileges
- none
- User Action
- required
- Scope
- unchanged
- Confidentiality
- high
- Integrity
- none
- Availability
- high
- Weaknesses
- CWE-284
Metadata
- Primary Vendor
- HCLTECH
- Published
- 3/26/2026
- Last Modified
- 3/26/2026
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
hcltech : aftermarket_cloud
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.