CVE-2025-52637 PUBLISHED

Multiple security vulnerabilities affect HCL AION

Assigner: HCL
Reserved: 18.06.2025 Published: 16.03.2026 Updated: 16.03.2026

HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific conditions.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 4.5

Product Status

Vendor HCL
Product AION
Versions Default: unaffected
  • Version 2.0 is affected

References