Information Disclosure Vulnerability in HCL AION Software
CVE-2025-62317

2.6LOW

Key Information:

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2025-62317?

HCL AION contains a vulnerability where sensitive information may inadvertently be included in URL parameters. This can result in the unintentional exposure of private data through browser history, server logs, and intermediary systems, posing a potential risk of data leaks in various scenarios. Users should be mindful of how sensitive information is handled within the application to mitigate this risk.

Affected Version(s)

AION 2.1.0

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.