Executive brief
HCL AION is a software platform used for business operations and data management. A security vulnerability has been identified where certain system operations can trigger unexpected communications with external systems. This could lead to the accidental disclosure of sensitive business information to unauthorized third parties under specific conditions.
Technical details
HCL AION is vulnerable to an information disclosure flaw (CWE-201) where specific operations trigger out-of-band (OOB) interactions. The vulnerability is characterized by the insertion of sensitive information into data sent to external systems. Exploitation requires an attacker to be on an adjacent network, have low-level privileges, and involves high complexity with a requirement for user interaction. If successfully exploited, this could lead to a loss of confidentiality, integrity, and availability, though the impact is limited. The issue was disclosed by HCL Software, and further details regarding specific versions or patches are available in their customer support portal.
Affected products
- HCL AION
Timeline
- 2026-05-14: disclosed: Initial advisory publication by HCL Software