Description
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific conditions.
Published: 2026-03-16
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure via SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows certain configurations within HCL AION to execute arbitrary SQL queries. If an attacker can influence these configurations, they could cause unintended database interactions, potentially leaking sensitive data or executing harmful queries. The weakness is a classic SQL injection flaw that could compromise confidentiality and integrity. The impact is limited to the data exposed by the compromised queries rather than complete system takeover.

Affected Systems

HCL AION is the affected product. No specific product versions are listed in the CNA data, so all installations of HCL AION are potentially vulnerable unless otherwise patched by HCL. No other vendors or products are named.

Risk and Exploitability

The CVSS score is 4.5, indicating moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors require the attacker to modify or input configuration settings that enable the execution of arbitrary SQL, which could be through internal users, compromised accounts, or improperly secured configuration interfaces. This information is inferred from the description; specific exploitation steps are not detailed.

Generated by OpenCVE AI on March 27, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any available HCL AION patch or update that addresses this SQL injection issue.
  • Review and tighten configuration options that permit arbitrary SQL execution, ensuring only safe and whitelisted queries can run.
  • Validate all inputs that influence query construction and avoid direct user input in SQL without sanitization.
  • Use a database account with the least privileges necessary for the application to run.
  • Enable logging and monitor for suspicious query activity to detect potential exploitation attempts.

Generated by OpenCVE AI on March 27, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 30 Mar 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech aion
Vendors & Products Hcltech
Hcltech aion

Fri, 27 Mar 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcl
Hcl aion
CPEs cpe:2.3:a:hcl:aion:*:*:*:*:*:*:*:*
Vendors & Products Hcl
Hcl aion

Mon, 16 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 13:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Mon, 16 Mar 2026 12:45:00 +0000

Type Values Removed Values Added
Description HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific conditions.
Title Multiple security vulnerabilities affect HCL AION
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-03-16T14:54:07.756Z

Reserved: 2025-06-18T14:00:43.106Z

Link: CVE-2025-52637

cve-icon Vulnrichment

Updated: 2026-03-16T14:53:57.945Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-16T14:17:59.457

Modified: 2026-03-27T17:31:23.220

Link: CVE-2025-52637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T08:00:24Z

Weaknesses