# CVE-2025-52633

## Summary

- **CVE ID:** CVE-2025-52633
- **Severity:** LOW
- **CVSS Score:** 3.1 (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L)
- **CWE:** CWE-539
- **Published:** Feb 3, 2026
- **Last Modified:** Mar 13, 2026

## Description

HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.

## Affected Products

- HCL — AION (2.0)

## References

- [CNA](https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127972)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 8.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._