CVE-2025-52633
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L
- EPSS probability
- 0.19%
- CWE
- CWE-539
- Published
- 2026-02-03
- Last modified
- 2026-03-13
Affected products
- HCL AION
Weakness type
Related vulnerabilities
- CVE-2026-35192 — Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST
- CVE-2026-24318 — Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
- CVE-2024-39275 — Advantech ADAM-5630 Use of Persistent Cookies Containing Sensitive Information
- CVE-2023-30861 — Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
- CVE-2021-27463 — A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer....