CVE 3.1 LOW

HCL AION is susceptible to Missing Content-Security-Policy_CVE-2025-52633

3.1 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L

Description

HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.

Basic Information

ID CVE-2025-52633
Source HCL
Published Feb 3, 2026 at 18:00
Modified Feb 3, 2026 at 18:55

Affected Product

Vendor HCL
Product AION
Version 2.0
Affected Versions HCL AION 2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.