HCL Aftermarket DPC Missing Functional Level Access Control Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability in HCL Aftermarket DPC version 1.0.0 has been identified, characterized by missing functional level access control. This vulnerability allows attackers to escalate privileges, potentially compromising the application and enabling the theft and manipulation of data.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing attackers to gain elevated rights within the application. This could result in a broader compromise of the application’s integrity and confidentiality, with potential unauthorized access to or manipulation of sensitive data.

Remediation

This vulnerability has been remediated through backend development.

Added: Mar 26, 2026, 2:29 PM
Updated: Mar 26, 2026, 2:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.