CVE-2025-55264 - HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change
CVE ID :CVE-2025-55264
Published : March 26, 2026, 2:16 p.m. | 47 minutes ago
Description :HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 26, 2026, 2:16 p.m. | 47 minutes ago
Description :HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...