Home

Description

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.

PUBLISHED Reserved 2025-06-18 | Published 2026-06-04 | Updated 2026-06-04 | Assigner HCL




LOW: 3.1CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Product status

Default status
unaffected

4.0.0
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0131061

cve.org (CVE-2025-52608)

nvd.nist.gov (CVE-2025-52608)

Download JSON