Junglewise Threat Intelligence

CVE-2025-62309: HCL AION sensitive information disclosure via browser autocomplete

CVE-2025-62309 · Severity: low · CVSS 2.6 · Published 2026-05-14

Technologies: HCL AION. Vendors: HCL.

Executive brief

HCL AION, a business software platform, contains a configuration issue where sensitive information entered into certain forms may be automatically saved by web browsers. If an unauthorized person gains access to a user's computer or browser profile, they could potentially view this cached sensitive data. This risk is primarily limited to shared workstations or compromised user accounts.

Technical details

HCL AION fails to disable the autocomplete attribute on sensitive input fields, leading to a violation of CWE-201 (Insertion of Sensitive Information Into Sent Data). This allows a web browser to cache and store sensitive user input locally. An attacker with adjacent network access and low privileges would require user interaction (such as a user leaving their session unattended or a browser profile being compromised) to extract the stored information. The vulnerability is rated low severity due to the high complexity of exploitation and the requirement for local or adjacent access to the user's environment. Users should refer to HCL KB0130636 for remediation guidance.

Affected products

  • HCL AION

Timeline

  • 2026-05-14: advisory: Initial disclosure by HCL Software

References

Related threats