HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover. | |
| Title | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-03-26T13:04:01.614Z
Reserved: 2025-08-12T06:59:56.644Z
Link: CVE-2025-55264
No data.
Status : Received
Published: 2026-03-26T14:16:08.157
Modified: 2026-03-26T14:16:08.157
Link: CVE-2025-55264
No data.
OpenCVE Enrichment
No data.