CVE-2025-52608 PUBLISHED

HCL iControl was affected by Missing Cookie Attributes vulnerability.

Assigner: HCL
Reserved: 18.06.2025 Published: 04.06.2026 Updated: 04.06.2026

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 3.1

Product Status

Vendor HCL
Product iControl
Versions Default: unaffected
  • Version 4.0.0 is affected

References

Problem Types

  • CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute CWE