CVE-2025-62311: HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels.
HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62311?
CVE-2025-62311 has been identified as a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2025-62311?
To fix CVE-2025-62311, ensure that backend service details are transmitted over secure HTTPS channels instead of insecure HTTP.
What systems are affected by CVE-2025-62311?
CVE-2025-62311 affects HCL AION products that transmit backend service details over insecure HTTP channels.
What kind of information is at risk with CVE-2025-62311?
CVE-2025-62311 may expose sensitive backend service details, which can lead to information interception.
Is there a workaround for CVE-2025-62311 until a fix is applied?
A temporary workaround for CVE-2025-62311 includes implementing secure channel communications and avoiding HTTP for sensitive transactions.