Impact
HCL AION contains a flaw where several input fields do not enforce sufficient server-side validation. Because unexpected or crafted data can be accepted, the application may exhibit unintended behavior or experience a security impact under certain conditions. This vulnerability is classified as CWE-116, which involves improper handling of input data.
Affected Systems
The affected system is HCL Software’s AION product. No specific versions are listed in the public advisory, so any deployed instance may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 3.4 indicates low overall severity and the EPSS score is not available, suggesting the current exploit probability is uncertain. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through user-submitted data, such as web form input, where an attacker could craft inputs that bypass server checks. While no known active exploitation is documented, the low severity combined with the potential for unforeseen application errors warrants cautious assessment.
OpenCVE Enrichment