CNNVD-202602-314 Information

CNNVD ID

CNNVD-202602-314

CVE-2025-52623

  • CNNVD Published: 2026-02-03

Description (Chinese)

HCL AION是印度HCL公司的一款AI生命周期管理平台。 HCL AION 2.0版本存在安全漏洞,该漏洞源于密码字段未禁用自动完成功能,可能导致敏感凭据被存储或泄露。

Description (English)

HCL AION is an AI life-cycle management platform for HCL India. There is a security loophole in HCL AION 2.0, which stems from the fact that the password field does not disable automatic completion, which may lead to sensitive evidence being stored or leaked.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

HCL

Published

2026-02-03

Last Modified

2026-02-24

References

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127972 https://access.redhat.com/security/cve/cve-2025-52623

Patch

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127972

Share on: