PT-2026-5904 · Hcl+1 · Aion

Published

2026-02-03

·

Updated

2026-02-11

·

CVE-2025-52628

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HCL AION version 2.0
Description HCL AION is susceptible to a cookie handling issue where cookies may lack proper SameSite attributes, or have insecure or improper configurations. This can allow cookies to be transmitted in unintended cross-site requests, potentially exposing the system to cross-site request forgery and similar security threats.
Recommendations Ensure that the SameSite attribute is correctly configured for all cookies used by HCL AION version 2.0. Implement the 'Strict' or 'Lax' SameSite attribute to prevent cross-site request forgery attacks.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-52628

Affected Products

Aion