Junglewise Threat Intelligence

CVE-2025-62316: HCL AION missing security headers

CVE-2025-62316 · Severity: low · CVSS 2.3 · Published 2026-05-14

Technologies: HCL AION. Vendors: HCL.

Executive brief

HCL AION is a software platform that lacks certain security-related configuration settings in its web interface. This omission could allow a limited range of browser-based attacks, such as clickjacking, which might trick users into performing unintended actions. The risk is considered low as it requires specific conditions and user interaction to be exploited.

Technical details

HCL AION fails to implement or properly configure security-related HTTP response headers, specifically relating to CWE-1021 (Improper Restriction of Rendered UI Layers or Frames). This vulnerability typically involves the absence of headers like X-Frame-Options or Content-Security-Policy (CSP) frame-ancestors. An attacker on an adjacent network with low privileges could potentially leverage this to conduct clickjacking or other UI-redressing attacks, though it requires high complexity and user interaction. The impact is limited to minor information disclosure (Confidentiality: Low) with no impact on integrity or availability.

Affected products

  • HCL AION

Timeline

  • 2026-05-14: advisory: NVD published the CVE record based on HCL Software's advisory.

References

Related threats