Sensitive Session Information Vulnerability in HCL AION
CVE-2025-52633
3.1LOW
What is CVE-2025-52633?
HCL AION is vulnerable to an issue where sensitive session information is stored in persistent cookies. This practice heightens the risk of unauthorized access, especially if the cookies are intercepted or compromised by malicious actors. It is critical for users to evaluate the security settings of their AION deployments to mitigate the potential for exploitation through this vulnerability.
Affected Version(s)
AION 2.0