PT-2026-5904 · Hcl+1 · Aion
CVE-2025-52628
·
Publicado
2026-02-03
·
Atualizado
2026-02-11
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HCL AION version 2.0
Description
HCL AION is susceptible to a cookie handling issue where cookies may lack proper SameSite attributes, or have insecure or improper configurations. This can allow cookies to be transmitted in unintended cross-site requests, potentially exposing the system to cross-site request forgery and similar security threats.
Recommendations
Ensure that the SameSite attribute is correctly configured for all cookies used by HCL AION version 2.0. Implement the 'Strict' or 'Lax' SameSite attribute to prevent cross-site request forgery attacks.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aion