CVE-2024-30155: Hcltech Hcl Sx

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

Affected products

Published 2025-03-26. Last modified 2026-06-17.