CVE-2025-62317 PUBLISHED

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters.

Assigner: HCL
Reserved: 10.10.2025 Published: 14.05.2026 Updated: 14.05.2026

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
CVSS Score: 2.6

Product Status

Vendor HCL
Product AION
Versions Default: unaffected
  • Version 2.1.0 is affected

References

Problem Types

  • CWE-598: Use of HTTP Request With Sensitive Query String CWE