CVE-2025-52631: HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability.
HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgrade attacks.. This issue affects AION: 2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52631?
CVE-2025-52631 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2025-52631?
To fix CVE-2025-52631, implement a secure HTTP Strict-Transport-Security (HSTS) header in your HCL AION application.
What are the potential risks of CVE-2025-52631?
The risks of CVE-2025-52631 include insecure connections and exposure of sensitive data during transmission.
Which versions of HCL AION are affected by CVE-2025-52631?
All versions of HCL AION are affected by CVE-2025-52631 due to the insecure implementation of HTTP headers.
Is there a public exploit for CVE-2025-52631?
As of now, there is no public exploit reported for CVE-2025-52631, but the vulnerability should still be addressed immediately.