CVE-2026-21832
- EPSS 0.22%
- Veröffentlicht 13.08.2026 13:24:30
- Zuletzt bearbeitet 13.08.2026 16:18:00
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions...
CVE-2025-62315
- EPSS 0.14%
- Veröffentlicht 13.08.2026 13:23:16
- Zuletzt bearbeitet 13.08.2026 16:17:52
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact...
CVE-2025-62318
- EPSS 0.09%
- Veröffentlicht 13.08.2026 13:21:29
- Zuletzt bearbeitet 13.08.2026 16:17:52
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain co...
CVE-2025-52640
- EPSS 0.09%
- Veröffentlicht 13.08.2026 13:17:16
- Zuletzt bearbeitet 13.08.2026 16:17:51
HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentia...
CVE-2025-62314
- EPSS 0.1%
- Veröffentlicht 13.08.2026 13:17:09
- Zuletzt bearbeitet 13.08.2026 16:17:52
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended beha...
CVE-2025-62305
- EPSS 0.11%
- Veröffentlicht 14.05.2026 16:17:33
- Zuletzt bearbeitet 14.05.2026 17:22:46
HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specif...
CVE-2025-62317
- EPSS 0.12%
- Veröffentlicht 14.05.2026 16:13:34
- Zuletzt bearbeitet 14.05.2026 17:22:46
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information ...
CVE-2025-62308
- EPSS 0.11%
- Veröffentlicht 14.05.2026 16:12:39
- Zuletzt bearbeitet 14.05.2026 17:22:46
HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis o...
CVE-2025-62309
- EPSS 0.12%
- Veröffentlicht 14.05.2026 16:10:49
- Zuletzt bearbeitet 14.05.2026 17:22:46
HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific conditions.
- EPSS 0.14%
- Veröffentlicht 14.05.2026 16:09:35
- Zuletzt bearbeitet 14.05.2026 17:22:46
HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse, especially if not combined with secure transmissio...