CVE-2025-52614: Hcltech Unica

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.

Affected products

  • Hcltech Unica: up to and including 25.1.0

Published 2025-10-12. Last modified 2026-10-08.