CVE-2025-52614Low· 3.5▾ SunlitHCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.
unica <= 25.1.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-52615Low· 3.5HCL Unica Platform is impacted by misconfigured security related HTTP headers
CVE-2025-31969Medium· 4.0HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP)
CVE-2025-52616Medium· 5.3HCL Unica 12.1.10 can expose sensitive system information
CVE-2025-52632Medium· 6.5A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
CVE-2025-31996Medium· 5.3HCL Unica Platform is affected by unprotected files due to improper access controls
CVE-2026-56599Low· 2.2HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabli…