Description
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.
CVSS Metrics
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L
- Attack Vector
- network
- Complexity
- high
- Privileges
- high
- User Action
- required
- Scope
- unchanged
- Confidentiality
- low
- Integrity
- none
- Availability
- low
- Weaknesses
- CWE-539
Metadata
- Primary Vendor
- HCLTECH
- Published
- 2/3/2026
- Last Modified
- 2/11/2026
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
hcltech : aion
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.