Home
LOW: 2.6 CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:NDefault status
unaffected
2.1.0
affected
Description
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.
Problem types
CWE-598: Use of HTTP Request With Sensitive Query String
Product status
2.1.0
References
support.hcl-software.com/...rticle&sysparm_article=KB0130636