Home

Description

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.

PUBLISHED Reserved 2025-10-10 | Published 2026-05-14 | Updated 2026-05-14 | Assigner HCL




LOW: 2.6CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

Problem types

CWE-598: Use of HTTP Request With Sensitive Query String

Product status

Default status
unaffected

2.1.0
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0130636

cve.org (CVE-2025-62317)

nvd.nist.gov (CVE-2025-62317)

Download JSON