CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.

Scoring

Severity
LOW
CVSS base score
2.6
CVSS vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
EPSS probability
0.11%
CWE
CWE-598
Published
2026-05-14
Last modified
2026-05-14

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs