HCL AION Basic Authorization Vulnerability Allowing Credential Interception
Vulnerability
A vulnerability exists in HCL AION v2.1.0, where basic authorization tokens are used for authentication. This approach may expose credentials to interception or misuse, particularly if not paired with secure transmission practices.
Impact
Exploitation of this vulnerability could lead to interception or unauthorized use of credentials, allowing for potential unauthorized access to accounts or services.
Remediation
Users can upgrade to HCL AION v2.5.0, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.
Added: May 14, 2026, 5:48 PM
Updated: May 14, 2026, 5:48 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
4.0remediation
0.0relevance
8.3threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
