CVE-2025-52615
BaseFortify
Publication date: 2025-10-12
Last updated on: 2025-10-20
Assigner: HCL Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcltech | unica | to 25.1.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves misconfigured security-related HTTP headers in the HCL Unica Platform. Because these headers are not properly set, browsers may apply less secure default policies, potentially reducing the overall security of web interactions with the platform.
How can this vulnerability impact me? :
The impact of this vulnerability is that it may allow browsers to treat the platform's web content with less secure default settings, which could increase the risk of certain web-based attacks or data exposure due to weaker security controls enforced by the browser.