HCL
HCL Aion: vulnerabilidades y CVE
HCL Aion tiene 17 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses17
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21832 | Media (4.3) | 0.29% | — | 13 ago 2026 | HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security… |
| CVE-2025-62318 | Baja (3.7) | 0.12% | — | 13 ago 2026 | HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page… |
| CVE-2025-62315 | Baja (3.4) | 0.21% | — | 13 ago 2026 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in… |
| CVE-2025-62314 | Media (5.6) | 0.15% | — | 13 ago 2026 | HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms,… |
| CVE-2025-52640 | Media (4.7) | 0.11% | — | 13 ago 2026 | HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond… |
| CVE-2025-62317 | Baja (2.6) | 0.11% | — | 14 may 2026 | HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially… |
| CVE-2025-62316 | Baja (2.3) | 0.11% | — | 14 may 2026 | HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and… |
| CVE-2025-62313 | Media (5.4) | 0.18% | — | 14 may 2026 | HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account… |
| CVE-2025-62312 | Baja (3) | 0.14% | — | 14 may 2026 | HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse, especially if not… |
| CVE-2025-62311 | Media (4.3) | 0.08% | — | 14 may 2026 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during… |
| CVE-2025-62310 | Media (5.4) | 0.05% | — | 14 may 2026 | HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under… |
| CVE-2025-62309 | Baja (2.6) | 0.11% | — | 14 may 2026 | HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure… |
| CVE-2025-62308 | Media (5.1) | 0.11% | — | 14 may 2026 | HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may… |
| CVE-2025-62305 | Media (5.1) | 0.11% | — | 14 may 2026 | HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data… |
| CVE-2025-52648 | Crítica (9.8) | 0.12% | — | 16 mar 2026 | HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity… |
| CVE-2025-52638 | Alta (7.2) | 0.13% | — | 16 mar 2026 | HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated… |
| CVE-2025-52637 | Alta (7.3) | 0.22% | — | 16 mar 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to… |