HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131061 | Vendor Advisory |
Configurations
History
04 Jun 2026, 18:38
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Hcltech icontrol
Hcltech |
|
| CPE | cpe:2.3:a:hcltech:icontrol:4.0.0:*:*:*:*:*:*:* | |
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131061 - Vendor Advisory |
04 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 12:16
Updated : 2026-06-04 18:38
NVD link : CVE-2025-52608
Mitre link : CVE-2025-52608
CVE.ORG link : CVE-2025-52608
JSON object : View
Products Affected
hcltech
- icontrol
CWE
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
