Vulnerability Description
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Aftermarket Cloud | 1.0.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-55264?
CVE-2025-55264 is a vulnerability with a CVSS score of 5.5 (MEDIUM). HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password cha...
How severe is CVE-2025-55264?
CVE-2025-55264 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55264?
Check the references section above for vendor advisories and patch information. Affected products include: Hcltech Aftermarket Cloud.