CVE-2025-52632: HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
Published Oct 10, 2025
·Updated
A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
Affected Software
2 affected components
HCL AION
hcltech Aion=2.0.0
Event History
Oct 10, 2025
CVE Published
via MITRE·10:06 AM
Data Sourced
via MITRE·10:06 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52632?
CVE-2025-52632 has been classified as a medium severity vulnerability.
2
What is the impact of CVE-2025-52632 on HCL AION?
CVE-2025-52632 allows attackers to exploit missing secure attributes in encrypted session cookies which can lead to session hijacking.
3
How do I fix CVE-2025-52632?
To remediate CVE-2025-52632, ensure that secure attributes are properly set for SSL cookies in HCL AION.
4
Which versions of HCL AION are affected by CVE-2025-52632?
CVE-2025-52632 affects HCL AION version 2.0.
5
Is there a workaround for CVE-2025-52632 if I cannot immediately patch?
Implementing additional security measures, such as using HttpOnly and Secure flags for cookies can help mitigate the risk until a patch is applied for CVE-2025-52632.