Executive brief
HCL AION is a platform used for business process automation and AI-driven operations. A security flaw has been identified where the system may transmit backend service details over unencrypted HTTP connections instead of secure HTTPS. This could allow an attacker on the same local network to intercept sensitive configuration data, potentially leading to unauthorized access or further exploitation of the business environment.
Technical details
HCL AION is vulnerable to CWE-319 (Cleartext Transmission of Sensitive Information) because it may transmit backend service details over insecure HTTP channels. The vulnerability requires an attacker to be on an adjacent network (AV:A) and involves high complexity (AC:H), requiring specific conditions and potentially user interaction (UI:R) to successfully intercept the data. If exploited, an attacker can capture sensitive information during transmission, which could facilitate further attacks against the backend infrastructure. Users are advised to refer to HCL Software's security bulletin KB0130636 for remediation steps.
Affected products
- HCL AION
Timeline
- 2026-05-14: disclosed: Initial disclosure by HCL Software
- 2026-05-14: advisory: NVD record published