HCL AION Boolean-Based SQL Injection Vulnerability
Vulnerability
A Boolean-based blind SQL injection vulnerability has been identified in HCL AION version 2.0. This vulnerability allows attackers to manipulate SQL queries by injecting Boolean conditions into application input fields. Instead of displaying database errors or visible data, the application responds based on the evaluation of the injected conditions. This behavior enables attackers to inject arbitrary SQL into backend configuration queries executed within the application.
Impact
Exploitation of this vulnerability could lead to unauthorized database access or manipulation, allowing attackers to execute arbitrary SQL commands or access sensitive data.
Remediation
Users can upgrade to HCL AION version 2.1.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
