HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
History

Wed, 26 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 08:15:00 +0000

Type Values Removed Values Added
Description HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
Title HCL SX is susceptible to cookie with Insecure, Improper, or Missing SameSite attribute vulnerability
Weaknesses CWE-1275
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2025-03-26T07:59:52.442Z

Updated: 2025-03-26T14:29:40.392Z

Reserved: 2024-03-22T23:57:26.414Z

Link: CVE-2024-30155

cve-icon Vulnrichment

Updated: 2025-03-26T14:29:34.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-26T08:15:12.657

Modified: 2025-03-27T16:45:46.410

Link: CVE-2024-30155

cve-icon Redhat

No data.