CVE 3.1 LOW

HCL iControl was affected by Missing Cookie Attributes vulnerability._CVE-2025-52608

3.1 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.

Basic Information

ID CVE-2025-52608
Source HCL
Published Jun 4, 2026 at 11:49

Affected Product

Vendor HCL
Product iControl
Version 4.0.0
Affected Versions HCL iControl 4.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.