CVE-2025-55249

Severity CVSS v4.0:
Pending analysis
Type:
CWE-693 Protection Mechanism Failure
Publication date:
19/01/2026
Last modified:
30/01/2026

Description

HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:aion:2.0:*:*:*:*:*:*:*