Impact
AION’s architecture allows several components to share a storage area that lacks proper separation controls. Because processes run by those components can access the shared files, they may read or modify data that was not intended for them. If an attacker can get code executed within any of these processes, they could potentially compromise other components, access sensitive data, or alter configuration files, thereby enabling unauthorized actions.
Affected Systems
The vulnerability affects HCL Software’s AION product. No specific version information is provided, so all installed instances of AION might be impacted.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker would need to execute code within one of the AION components that share the vulnerable storage. Successful exploitation could lead to elevation of privileges or unauthorized file access, with a limited but non‑negligible risk of data exposure or tampering.
OpenCVE Enrichment