---
id: CVE-2025-62317
title: >-
  HCL AION is affected by a vulnerability where sensitive information may be
  included in URL parameters
summary: >-
  HCL AION is affected by a vulnerability where sensitive information may be
  included in URL parameters. Passing sensitive data in URLs may expose it
  through browser history, logs, or intermediary systems, potentially leading to
  unintended…
severity: low
cvss: 2.6
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N'
cwe:
  - CWE-598
published: '2026-05-14'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62317'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130636
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00115
epssPercentile: 0.01418
ingestedAt: '2026-09-30T21:25:07.729Z'
---

## Overview

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
