Impact
The vulnerability is the absence of certain security‑related HTTP response headers in HCL AION, which weakens browser‑based defenses such as X‑Frame‑Options, Content‑Security‑Policy, and X‑Content‑Type‑Options. This can enable attacks that rely on these controls, potentially allowing script injection or click‑jacking under specific conditions. The weakness is identified as CWE‑1021, pointing to improper configuration of response headers.
Affected Systems
The issue affects HCL AION installations. No specific product versions are listed, so all current AION instances lacking the proper headers are impacted. Administrators should audit any running instances of AION to confirm header presence.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score is not available. The vulnerability is not in the CISA KEV catalog. The likely attack vector is remote, via HTTP requests to the AION server, because the problem concerns omitted response headers. Exploitation would rely on a crafted request that triggers a response missing the security headers, thereby weakening browser protections. Overall, the risk is low but the vulnerability is actionable.
OpenCVE Enrichment