HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information disclosure.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 | Vendor Advisory |
Configurations
History
23 Mar 2026, 14:35
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:hcltech:aion:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| First Time |
Hcltech aion
Hcltech |
|
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 - Vendor Advisory |
16 Mar 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-538 |
16 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 15:16
Updated : 2026-03-23 14:35
NVD link : CVE-2025-52642
Mitre link : CVE-2025-52642
CVE.ORG link : CVE-2025-52642
JSON object : View
Products Affected
hcltech
- aion
CWE
CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
