HCL AION Predictable Identifier Vulnerability Allowing Limited Information Disclosure

Vulnerability

A vulnerability exists in HCL AION version 2.0, where certain identifiers may be predictable. This predictability can allow an attacker to infer or guess system-generated values, potentially leading to limited information disclosure or unintended access under specific conditions.

Impact

The vulnerability could result in limited information disclosure or unauthorized access, depending on the context in which the predictable identifiers are exploited.

Remediation

Users can upgrade to HCL AION version 2.1.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.

Added: Mar 16, 2026, 3:58 PM
Updated: Mar 16, 2026, 3:58 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.2
remediation
0.0
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.