AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2025-62318

LOW · CVSS 3.7 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

HCL AION is vulnerable due to JavaScript responses that can be accessed by external pages, enabling attackers to potentially capture sensitive information through JavaScript hijacking. Although the severity is rated low, organizations using HCL AION should prioritize remediation to mitigate the risk of data exposure. Developers and security teams should particularly focus on implementing proper security controls around JavaScript responses to prevent unauthorized access.

CVE
CVE-2025-62318
Severity
LOW
CVSS
3.7
EPSS
0.08%
Java

Original NVD Description

HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.