HCL AION Missing or Insecure HTTP Strict-Transport-Security Header Vulnerability
Vulnerability
A vulnerability exists in HCL AION version 2.0 due to a missing or insecure HTTP Strict-Transport-Security (HSTS) header. This absence can lead to insecure connections, making the application susceptible to man-in-the-middle and protocol downgrade attacks.
Impact
The lack of a proper HSTS header can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgrade attacks.
Remediation
Users can upgrade to HCL AION version 2.1.0, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION Product support team.
Added: Feb 3, 2026, 7:47 PM
Updated: Feb 3, 2026, 7:47 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
6.7exploitability
4.2remediation
0.0relevance
2.5threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
