CVE-2025-52608: fallo de gravedad baja en HCL iControl
HCL iControl was affected by Missing Cookie Attributes vulnerability.
Publicada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 3.1epss 0.1%
probabilidad de explotación
0.1%top 99% de las CVE
explotación observada
noninguna fuente lo reporta
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Productos afectados
HCL · iControlCVEs relacionadas — HCL iControl
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-52612HIGHHCL iControl was affected by Export CSV - CSV Injection vulnerability.EPSS 0.2%CVE-2025-52606MEDIUMHCL iControl was affected by Weak Input Validation vulnerability. .EPSS 0.2%CVE-2025-52609LOWHCL iControl was affected by Missing Security Headers vulnerability.EPSS 0.2%CVE-2025-52611LOWHCL iControl was affected by Unhandled Exception - Stack Trace Disclosure vulnerabilityEPSS 0.2%