漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change
Vulnerability Description
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
HCL Aftermarket DPC 安全漏洞
Vulnerability Description
HCL Aftermarket DPC是印度HCL公司的一个数字化备件与售后服务管理平台。 HCL Aftermarket DPC存在安全漏洞,该漏洞源于密码更改时未能使会话失效,可能导致攻击者在访问会话后,尽管密码已更改,仍能维持对账户的控制,从而导致账户接管。
CVSS Information
N/A
Vulnerability Type
N/A