CVE-2025-52644: medium-severity vulnerability in HCL AION
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.8epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation processes.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Affected products
HCL · AIONRelated CVEs — HCL AION
In the same product, most dangerous first.
CVE-2025-52626MEDIUMHCL AION is susceptible to Potential Command Injection vulnerabilityEPSS 0.7%CVE-2025-52635LOWHCL AION is susceptible to Trusted types in scripts not enforced in CSPEPSS 0.3%CVE-2025-52631LOWHCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability.EPSS 0.2%CVE-2025-52625LOWHCL AION is susceptible to Cacheable SSL Page Found vulnerabilityEPSS 0.2%CVE-2025-52630LOWHCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerabilityEPSS 0.2%CVE-2025-52628MEDIUMHCL AION is susceptible to Missing SameSite vulnerabilityEPSS 0.2%