Unrated severityNVD Advisory· Published Mar 26, 2026· Updated Mar 26, 2026
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change
CVE-2025-55264
Description
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
Affected products
2- HCL/Aftermarket DPCv5Range: version 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.