CVE-2025-52630: HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerability
Published Oct 10, 2025
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
Affected Software
2 affected components
HCL AION
hcltech Aion=2.0.0
Event History
Oct 10, 2025
CVE Published
via MITRE·09:55 AM
Data Sourced
via MITRE·09:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52630?
CVE-2025-52630 is rated as a high severity vulnerability due to its potential for exposing sensitive information.
2
How do I fix CVE-2025-52630?
To mitigate CVE-2025-52630, update to the latest version of HCL AION where the vulnerability is resolved.
3
What types of sensitive information are exposed by CVE-2025-52630?
CVE-2025-52630 potentially exposes sensitive user data, including personal and sensitive configuration settings.
4
Who is affected by CVE-2025-52630?
All users of HCL AION 2.0 are affected by CVE-2025-52630.
5
What can happen if CVE-2025-52630 is exploited?
If exploited, CVE-2025-52630 may allow unauthorized actors to access confidential information, leading to privacy breaches.