CVE-2025-62317
Estado: AplazadaBaja (2.6)—
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.11%
- Percentil entre todas las CVEs puntuadas: 1
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-598
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-62317",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-62317",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-14T18:31:31.916059Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 2.6,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "psirt@hcl.com",
"affectedData": [
{
"vendor": "HCL",
"product": "AION",
"versions": [
{
"status": "affected",
"version": "2.1.0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-14T17:16:19.107",
"references": [
{
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130636",
"source": "psirt@hcl.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"description": [
{
"lang": "en",
"value": "CWE-598"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions."
},
{
"lang": "es",
"value": "HCL AION se ve afectado por una vulnerabilidad donde información sensible puede ser incluida en los parámetros de la URL. Pasar datos sensibles en las URLs puede exponerlos a través del historial del navegador, registros o sistemas intermediarios, lo que podría llevar a una revelación de información no intencionada bajo ciertas condiciones."
}
],
"lastModified": "2026-09-30T21:10:00.190",
"sourceIdentifier": "psirt@hcl.com"
}