CVE-2025-62317: Hcl Aion

Low severity, CVSS 2.6. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.

Affected products

  • Hcl Aion: version 2.1.0 only

Published 2026-05-14. Last modified 2026-10-07.