|
1371
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibili…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-55249
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1372
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de encabezados de respuesta de seguridad faltantes. La ausencia de encabezados de seguridad estándar puede debilitar la postura de seguridad general de l…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-55249
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1373
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-55251
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1374
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de carga de archivos sin restricciones. Esto puede permitir cargas de archivos maliciosos, lo que podría resultar en ejecución de código no autorizada o …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-55251
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1375
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access
|
CWE-521
Weak Password Requirements
|
CVE-2025-55252
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1376
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectado por una vulnerabilidad de política de contraseñas débil. Esto puede permitir el uso de contraseñas fácilmente adivinables, lo que podría resultar en acceso no autoriz…
|
CWE-521
Weak Password Requirements
|
CVE-2025-55252
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1377
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2025-55250
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1378
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectado por una vulnerabilidad de revelación de errores técnicos. Esto puede exponer detalles técnicos sensibles, lo que podría resultar en revelación de información o facili…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2025-55250
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1379
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
|
CWE-613
Insufficient Session Expiration
|
CVE-2025-52661
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1380
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectada por una vulnerabilidad de JWT Token Expiry Too Long. Esto puede aumentar el riesgo de uso indebido del token, lo que podría resultar en acceso no autorizado si el tok…
|
CWE-613
Insufficient Session Expiration
|
CVE-2025-52661
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|