HCL AION Permanent Cookie Vulnerability Allowing Sensitive Session Information Exposure
Vulnerability
A vulnerability exists in HCL AION version 2.0, where sensitive session data is stored in permanent cookies. This practice increases the risk of unauthorized access if the cookies are intercepted or compromised.
Impact
Exploitation of this vulnerability could lead to unauthorized access by allowing interception or compromise of sensitive session information stored in cookies.
Remediation
Users can upgrade to HCL AION version 2.1.0, which addresses this vulnerability. For assistance with the upgrade, contact the HCL AION Product support team.
Added: Feb 3, 2026, 7:47 PM
Updated: Feb 3, 2026, 7:47 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
5.8remediation
0.0relevance
2.7threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
