CVE-2025-52644
high
CVSS v3
8.2
CVSS v2
—
VIR risk
8.2
Description
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation processes.
Predictions
Exploit likelihood
88%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@hcl.com — https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hcltech | aion | {"startIncluding":"2.0.0","endExcluding":"2.1.2"} | 2.1.2 |
References
CWEs
CWE-778
Verify integrity in audit chain (admin only). AS-IS.