CVE-2025-52608

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:icontrol:4.0.0:*:*:*:*:*:*:*

History

04 Jun 2026, 18:38

Type Values Removed Values Added
First Time Hcltech icontrol
Hcltech
CPE cpe:2.3:a:hcltech:icontrol:4.0.0:*:*:*:*:*:*:*
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131061 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131061 - Vendor Advisory

04 Jun 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 12:16

Updated : 2026-06-04 18:38


NVD link : CVE-2025-52608

Mitre link : CVE-2025-52608

CVE.ORG link : CVE-2025-52608


JSON object : View

Products Affected

hcltech

  • icontrol
CWE
CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute