HCL AION Basic Authorization Vulnerability Allowing Credential Interception

Vulnerability

A vulnerability exists in HCL AION v2.1.0, where basic authorization tokens are used for authentication. This approach may expose credentials to interception or misuse, particularly if not paired with secure transmission practices.

Impact

Exploitation of this vulnerability could lead to interception or unauthorized use of credentials, allowing for potential unauthorized access to accounts or services.

Remediation

Users can upgrade to HCL AION v2.5.0, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.

Added: May 14, 2026, 5:48 PM
Updated: May 14, 2026, 5:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
8.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.