HCL AION Predictable Identifier Vulnerability Allowing Limited Information Disclosure
Vulnerability
A vulnerability exists in HCL AION version 2.0, where certain identifiers may be predictable. This predictability can allow an attacker to infer or guess system-generated values, potentially leading to limited information disclosure or unintended access under specific conditions.
Impact
The vulnerability could result in limited information disclosure or unauthorized access, depending on the context in which the predictable identifiers are exploited.
Remediation
Users can upgrade to HCL AION version 2.1.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
