An information exposure vulnerability exists in
Vulnerability in HCL Software ZIE for Web.
The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site linked from the application can hijack user sessions
This issue affects ZIE for Web: v16.
References
Configurations
No configuration.
History
26 Feb 2026, 22:20
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-598 | |
| Summary |
|
23 Feb 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-23 11:16
Updated : 2026-02-26 22:20
NVD link : CVE-2025-59873
Mitre link : CVE-2025-59873
CVE.ORG link : CVE-2025-59873
JSON object : View
Products Affected
No product.
CWE
CWE-598
Use of GET Request Method With Sensitive Query Strings
