HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific conditions.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 | Vendor Advisory |
Configurations
History
18 Mar 2026, 20:36
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:hcltech:aion:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 - Vendor Advisory | |
| First Time |
Hcltech aion
Hcltech |
16 Mar 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 |
16 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 15:16
Updated : 2026-03-18 20:36
NVD link : CVE-2025-52646
Mitre link : CVE-2025-52646
CVE.ORG link : CVE-2025-52646
JSON object : View
Products Affected
hcltech
- aion
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
