CVE-2025-52641Low· 2.9▾ SunlitHCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 16 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited information disclosure.
aion >= 2.0.0, < 2.1.2Upgrade past the affected range:
aion 2.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-31998Low· 3.5HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information
CVE-2025-31960Medium· 5.3HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module
CVE-2025-59853Low· 3.1HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code log…
CVE-2025-59872Medium· 4.3HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allo…
CVE-2025-8852Medium· 4.3A vulnerability was identified in WuKongOpenSource WukongCRM 11.0
CVE-2024-23689High· 8.8Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…