PT-2026-5904 · Hcl+1 · Aion
Published
2026-02-03
·
Updated
2026-02-11
·
CVE-2025-52628
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HCL AION version 2.0
Description
HCL AION is susceptible to a cookie handling issue where cookies may lack proper SameSite attributes, or have insecure or improper configurations. This can allow cookies to be transmitted in unintended cross-site requests, potentially exposing the system to cross-site request forgery and similar security threats.
Recommendations
Ensure that the SameSite attribute is correctly configured for all cookies used by HCL AION version 2.0. Implement the 'Strict' or 'Lax' SameSite attribute to prevent cross-site request forgery attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aion