HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.
The Secure attribute for sensitive cookies in HTTPS sessions is not set.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Unica | Hcltech | * | 25.1.0 (including) |