PT-2026-5907 · Hcl+1 · Aion
Published
2026-02-03
·
Updated
2026-04-27
·
CVE-2025-52633
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HCL AION version 2.0
Description
HCL AION is susceptible to a security issue involving the storage of sensitive session data in persistent cookies. This practice can elevate the risk of unauthorized access if these cookies are intercepted or compromised. The issue may lead to potential unauthorized access to user accounts and sensitive information.
Recommendations
Ensure sensitive session data is not stored in persistent cookies. Implement secure session management practices to protect against unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aion