VulnerabilityDeferred
CVE-2025-62317
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters.
LOW 2.6EPSS 0.11%
Does this matter?
Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.
Description
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.
- CVSS 3.1
- 2.6 LOWCVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
- EPSS
- 0.11% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-598
- Source
- psirt@hcl.com
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.