Skip to main content

Sensitive Cookie with Improper SameSite Attribute

CVE-2025-52628

Severity Medium
Score 4.6/10

Summary

HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • REQUIRED
  • LOW
  • NONE
  • LOW

CWE-1275 - Sensitive Cookie with Improper SameSite Attribute

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

References

Advisory Timeline

  • Published