Executive brief
HCL AION, a platform used for business operations and automation, is affected by a security flaw where sensitive information is transmitted within web addresses (URLs). This could allow unauthorized individuals to see private data by looking at browser history, server logs, or network monitoring tools. While the risk is low, it could lead to the exposure of credentials or other confidential business information.
Technical details
HCL AION is vulnerable to CWE-598 (Use of GET Request Method With Sensitive Query Strings). The application transmits sensitive data as part of the URL query parameters rather than in the body of a POST request. This behavior exposes sensitive information to any system that logs URLs, including browser history, web server access logs, and reverse proxies. Exploitation requires an attacker to have adjacent network access, low-level privileges, and involves high complexity with user interaction. Successful exploitation results in a limited loss of confidentiality.
Affected products
- HCL AION
Timeline
- 2026-05-14: advisory: HCL published the security bulletin KB0130636.
- 2026-05-14: disclosed: CVE-2025-62317 was published to the NVD.