HCL AION 存在一个漏洞,其 HTTP 响应头中未配置内容安全策略(Content-Security-Policy, CSP)。CSP 通过限制脚本、样式及其他资源的加载来源,有助于防范跨站脚本攻击(XSS)等威胁。缺少该响应头可能会削弱基于浏览器的安全控制机制的有效性,在某些条件下可能导致非预期行为或产生负面的安全影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | AION | Version 2.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66246 | 8.8 HIGH | HCL iControl is affected by multiple security vulnerabilities |
| CVE-2026-67105 | 7.4 HIGH | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-56589 | 7.2 HIGH | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67171 | 5.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67106 | 5.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67104 | 5.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2025-31980 | 4.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-66247 | 4.3 MEDIUM | iControl不安全CORS策略致敏感数据泄露漏洞 |
| CVE-2026-67172 | 3.7 LOW | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-66253 | 3.1 LOW | HCL iControl is affected by a Session Timeout vulnerability |
| CVE-2026-66249 | 3.1 LOW | HCL iControl is affected by a Missing Secure Attribute vulnerability |
| CVE-2026-66248 | 3.1 LOW | HCL iControl is affected by an Improper Error Handling vulnerability |
| CVE-2026-56599 | 2.2 LOW | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
No comments yet