HCL AION Insecure HTTP Transmission Vulnerability
Vulnerability
A vulnerability exists in HCL AION v2.1.0, where backend service details may be sent over unsecure HTTP channels. This could allow sensitive information to be intercepted or accessed without authorization during transmission, under certain conditions.
Impact
Exploitation of this vulnerability could lead to interception or unauthorized access to sensitive information being transmitted over HTTP.
Remediation
Users can upgrade to HCL AION v2.5.0, which addresses this vulnerability. The HCL AION support team can assist with the upgrade process.
Added: May 14, 2026, 5:35 PM
Updated: May 14, 2026, 5:35 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
4.2remediation
0.0relevance
8.3threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
