Impact
HCL AION exposes a missing Content-Security-Policy HTTP response header, a control that normally limits the origins from which scripts, styles, and other resources can be loaded. Without this header, the web application no longer actively blocks potentially unsafe content, which can reduce the effectiveness of browser defenses against cross‑site scripting and related injection attacks. The vulnerability could therefore allow attackers to leverage vulnerable browsers to inject or execute arbitrary scripts in the context of the application, resulting in confidentiality or integrity compromises under certain conditions.
Affected Systems
The affected product is HCL Software AION. No specific version ranges are listed, so all installations of AION may be impacted until a patch or configuration fix is applied.
Risk and Exploitability
The CVSS score of 3.7 indicates a low overall severity. The EPSS score is not available and the weakness is not listed in the CISA KEV catalog. Likely attack vector is through a victim’s browser; an attacker would need to deliver malicious content to a browser that accesses the affected application. Because the vulnerability only removes a mitigative header, exploitation requires a separate XSS vector, and the risk is considered low but not negligible.
OpenCVE Enrichment