nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-52608 CVE-2025-52608
LOW
HCL iControl was affected by Missing Cookie Attributes vulnerability.
Record summary
CVE-2025-52608 has a selected CVSS score of 3.1 (low).
Description
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
iControlBrowse HCL / iControlDefault status: unaffected | CVE List | 4.0.0 | affected |
References
2support.hcl-software.com
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131061