HCL AION Boolean-Based SQL Injection Vulnerability

Vulnerability

A Boolean-based blind SQL injection vulnerability has been identified in HCL AION version 2.0. This vulnerability allows attackers to manipulate SQL queries by injecting Boolean conditions into application input fields. Instead of displaying database errors or visible data, the application responds based on the evaluation of the injected conditions. This behavior enables attackers to inject arbitrary SQL into backend configuration queries executed within the application.

Impact

Exploitation of this vulnerability could lead to unauthorized database access or manipulation, allowing attackers to execute arbitrary SQL commands or access sensitive data.

Remediation

Users can upgrade to HCL AION version 2.1.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.

Added: Mar 16, 2026, 4:27 PM
Updated: Mar 16, 2026, 4:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
4.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.