HCL AION Untrusted File Parsing Vulnerability Allowing Potential Integrity Impact
Vulnerability
A vulnerability exists in HCL AION version 2.0, where untrusted file parsing operations are not conducted within a properly isolated sandbox environment. This lack of isolation may expose the application to security risks, including unintended behavior or integrity issues when handling specially crafted files.
Impact
Exploitation of this vulnerability could lead to unintended application behavior or integrity impacts, particularly when processing manipulated files.
Remediation
Users can upgrade to HCL AION version 2.1.2, which addresses this vulnerability. The HCL AION support team can assist with the upgrade process.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
