CVE-2025-12031 | Azure Access BLU-IC2/BLU-IC4 up to 1.19.5 cookie httponly flag
A vulnerability was found in Azure Access BLU-IC2 and BLU-IC4 up to 1.19.5. It has been declared as problematic. Impacted is an unknown function. The manipulation results in cookie without 'httponly' flag.
This vulnerability is reported as CVE-2025-12031. The attack can be launched remotely. No exploit exists.