CVE Vulnerabilities

CVE-2025-52614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: Oct 12, 2025 | Modified: Oct 20, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Affected Software

Name Vendor Start Version End Version
Unica Hcltech * 25.1.0 (including)

Potential Mitigations

References