Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.