Executive brief
HCL iControl, a business process monitoring and management solution, is affected by a configuration weakness where security flags are missing from its web cookies. This could allow an attacker to potentially intercept or manipulate session information if the connection is not properly secured. While the risk is low, it could lead to unauthorized access or session hijacking under specific network conditions.
Technical details
HCL iControl fails to set essential security attributes on HTTP cookies, specifically the 'Secure' and 'SameSite' flags. Additionally, the cookie path is overly broad, being set to the root directory ('/'). This vulnerability (CWE-614) means that cookies may be transmitted over unencrypted connections or be susceptible to Cross-Site Request Forgery (CSRF) and cross-site leakage. An attacker with network access and low privileges could potentially exploit these missing attributes to capture or manipulate session cookies. The issue is addressed in HCL's security bulletin KB0131061.
Affected products
- HCL iControl
Timeline
- 2026-06-04: disclosed: Initial disclosure by HCL Software
- 2026-06-04: advisory: NVD publication date