Impact
The vulnerability allows certain configurations within HCL AION to execute arbitrary SQL queries. If an attacker can influence these configurations, they could cause unintended database interactions, potentially leaking sensitive data or executing harmful queries. The weakness is a classic SQL injection flaw that could compromise confidentiality and integrity. The impact is limited to the data exposed by the compromised queries rather than complete system takeover.
Affected Systems
HCL AION is the affected product. No specific product versions are listed in the CNA data, so all installations of HCL AION are potentially vulnerable unless otherwise patched by HCL. No other vendors or products are named.
Risk and Exploitability
The CVSS score is 4.5, indicating moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors require the attacker to modify or input configuration settings that enable the execution of arbitrary SQL, which could be through internal users, compromised accounts, or improperly secured configuration interfaces. This information is inferred from the description; specific exploitation steps are not detailed.
OpenCVE Enrichment