Security Misconfiguration in HCL AION Affects Browser-Based Security Controls
CVE-2025-62316

2.3LOW

Key Information:

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2025-62316?

HCL AION possesses a vulnerability characterized by improperly configured security-related HTTP response headers. This misconfiguration can undermine the effectiveness of security measures implemented in web browsers, potentially leaving the application vulnerable under certain scenarios. If the relevant headers are absent, it may expose users to various security threats, emphasizing the need for proper configuration to ensure robust protection against such risks.

Affected Version(s)

AION 2.1.0

References

CVSS V3.1

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.