HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech aftermarket Cloud |
|
| CPEs | cpe:2.3:a:hcltech:aftermarket_cloud:1.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Hcltech
Hcltech aftermarket Cloud |
Thu, 26 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover. | |
| Title | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-03-26T18:35:17.005Z
Reserved: 2025-08-12T06:59:56.644Z
Link: CVE-2025-55264
Updated: 2026-03-26T18:35:13.832Z
Status : Analyzed
Published: 2026-03-26T14:16:08.157
Modified: 2026-03-26T19:52:55.690
Link: CVE-2025-55264
No data.
OpenCVE Enrichment
No data.