CVE-2025-52633: HCL AION is susceptible to Missing Content-Security-Policy
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52633?
CVE-2025-52633 is considered a high severity vulnerability due to the possible unauthorized access that can occur from exposed sensitive session information in persistent cookies.
How can I mitigate CVE-2025-52633?
To mitigate CVE-2025-52633, implement a Content-Security-Policy header and avoid storing sensitive session information in persistent cookies.
What systems are affected by CVE-2025-52633?
CVE-2025-52633 specifically affects the HCL AION software.
Is CVE-2025-52633 a permanent vulnerability?
Yes, CVE-2025-52633 is a permanent vulnerability as it allows sensitive information to be stored in persistent cookies.
What type of vulnerabilities does CVE-2025-52633 include?
CVE-2025-52633 includes vulnerabilities related to Missing Content-Security-Policy and insecure storage of session information.