HCL AION是印度HCL公司的一款AI生命周期管理平台。 HCL AION存在安全漏洞,该漏洞源于布尔型SQL注入,攻击者可通过在应用输入字段注入布尔条件来操纵SQL查询,可能导致将任意SQL注入后端配置查询。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-52644 | 5.8 MEDIUM | HCL AION is affected by a vulnerability where certain user actions are not adequately audi |
| CVE-2025-52638 | 5.6 MEDIUM | Multiple security vulnerabilities affect HCL AION |
| CVE-2025-52648 | 4.8 MEDIUM | HCL AION 安全漏洞 |
| CVE-2025-52643 | 4.7 MEDIUM | HCL AION is affected by a vulnerability where untrusted file parsing operations are not ex |
| CVE-2025-52637 | 4.5 MEDIUM | Multiple security vulnerabilities affect HCL AION |
| CVE-2025-52642 | 3.3 LOW | HCL AION is affected by an internal filesystem paths disloser vulnerability |
| CVE-2025-52646 | 2.2 LOW | HCL AION is affected by a vulnerability where certain offering configurations may permit e |
| CVE-2025-52645 | 1.9 LOW | HCL AION is affected by a vulnerability where model packaging and distribution mechanisms |
| CVE-2025-52649 | 1.8 LOW | HCL AION is affected by a vulnerability where certain identifiers may be predictable in na |
| CVE-2025-52636 | 1.8 LOW | HCL AION is affected by a improper handling of uploads files Size |
No comments yet