CVE-2025-52661

HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:aion:2.0.0:*:*:*:*:*:*:*

History

25 Apr 2026, 18:04

Type Values Removed Values Added
Summary
  • (es) HCL AION versión 2 está afectada por una vulnerabilidad de JWT Token Expiry Too Long. Esto puede aumentar el riesgo de uso indebido del token, lo que podría resultar en acceso no autorizado si el token se ve comprometido.
CPE cpe:2.3:a:hcltech:aion:2.0:*:*:*:*:*:*:* cpe:2.3:a:hcltech:aion:2.0.0:*:*:*:*:*:*:*

30 Jan 2026, 16:21

Type Values Removed Values Added
CPE cpe:2.3:a:hcltech:aion:2.0:*:*:*:*:*:*:*
First Time Hcltech aion
Hcltech
References () https://support.hcl-software.com/kb_view.do?sys_kb_id=4b92474633de7ad4159a05273e5c7b4b&searchTerm=kb0127995# - () https://support.hcl-software.com/kb_view.do?sys_kb_id=4b92474633de7ad4159a05273e5c7b4b&searchTerm=kb0127995# - Vendor Advisory

19 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-19 18:16

Updated : 2026-04-25 18:04


NVD link : CVE-2025-52661

Mitre link : CVE-2025-52661

CVE.ORG link : CVE-2025-52661


JSON object : View

Products Affected

hcltech

  • aion
CWE
CWE-613

Insufficient Session Expiration