HCL AION Sensitive Information Exposure Vulnerability via URL Parameters

Vulnerability

A vulnerability exists in HCL AION v2.1.0, where sensitive information may be inadvertently included in URL parameters. This issue can lead to unintentional data disclosure through browser history, logs, or intermediary systems, under certain conditions.

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure.

Remediation

Users can upgrade to HCL AION v2.5.0, which addresses this vulnerability. The HCL AION support team can assist with the upgrade process.

Added: May 14, 2026, 5:46 PM
Updated: May 14, 2026, 5:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.4
remediation
0.0
relevance
8.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.