HCL AION Untrusted File Parsing Vulnerability Allowing Potential Integrity Impact

Vulnerability

A vulnerability exists in HCL AION version 2.0, where untrusted file parsing operations are not conducted within a properly isolated sandbox environment. This lack of isolation may expose the application to security risks, including unintended behavior or integrity issues when handling specially crafted files.

Impact

Exploitation of this vulnerability could lead to unintended application behavior or integrity impacts, particularly when processing manipulated files.

Remediation

Users can upgrade to HCL AION version 2.1.2, which addresses this vulnerability. The HCL AION support team can assist with the upgrade process.

Added: Mar 16, 2026, 3:48 PM
Updated: Mar 16, 2026, 3:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.5
exploitability
2.8
remediation
0.0
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.