# CVE-2025-62317

## Summary

- **CVE ID:** CVE-2025-62317
- **Severity:** LOW
- **CVSS Score:** 2.6 (CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N)
- **CWE:** CWE-598
- **Published:** May 14, 2026
- **Last Modified:** May 14, 2026

## Description

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.

## Affected Products

- HCL — AION (2.1.0)

## References

- [CNA](https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130636)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._