CVE-2025-55264
EUVD-2025-20908526.03.2026, 14:16
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hcltech | aftermarket_cloud | 1.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration