Impact
The vulnerability in HCL Software iControl arises from a missing 'Secure' attribute on session cookies. As a result, cookies containing session identifiers can be transmitted over plain HTTP connections. An attacker who can observe this traffic—such as through a network sniffing or a man‑in‑the‑middle attack—may capture these cookies and gain unauthorized access to user sessions, leading to exploitation of confidential information and potential impersonation of legitimate users.
Affected Systems
The affected product is HCL Software’s iControl. No specific version numbers are disclosed in the advisory; administrators should verify which releases impacted by reviewing the vendor’s update page referenced in the advisory.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity, and the vulnerability is not listed in the CISA KEV catalog. However, the risk remains present because the exploitation path—capturing unencrypted cookies—can be performed by anyone with network visibility. No exploitable code execution is required, but session hijacking can grant extensive unauthorized access when an attacker successfully obtains a valid cookie.
OpenCVE Enrichment