CVE-2026-56456
- EPSS 0.24%
- Veröffentlicht 16.07.2026 13:15:35
- Zuletzt bearbeitet 17.07.2026 19:11:30
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system log...
CVE-2026-56455
- EPSS 0.27%
- Veröffentlicht 16.07.2026 13:13:21
- Zuletzt bearbeitet 17.07.2026 19:10:42
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory containe...
CVE-2026-56454
- EPSS 0.14%
- Veröffentlicht 16.07.2026 13:08:38
- Zuletzt bearbeitet 17.07.2026 19:10:04
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the...
CVE-2026-56453
- EPSS 0.19%
- Veröffentlicht 16.07.2026 13:06:49
- Zuletzt bearbeitet 17.07.2026 19:09:35
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate t...
CVE-2026-35145
- EPSS 0.17%
- Veröffentlicht 16.07.2026 13:05:30
- Zuletzt bearbeitet 17.07.2026 19:03:57
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade ...
CVE-2026-35143
- EPSS 0.11%
- Veröffentlicht 16.07.2026 13:04:04
- Zuletzt bearbeitet 17.07.2026 16:22:20
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Fo...
CVE-2026-35142
- EPSS 0.18%
- Veröffentlicht 16.07.2026 13:02:45
- Zuletzt bearbeitet 17.07.2026 16:27:03
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology info...
CVE-2026-35141
- EPSS 0.19%
- Veröffentlicht 16.07.2026 12:59:07
- Zuletzt bearbeitet 17.07.2026 16:44:13
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the applica...
CVE-2026-35140
- EPSS 0.16%
- Veröffentlicht 16.07.2026 12:48:11
- Zuletzt bearbeitet 17.07.2026 17:00:19
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to...
CVE-2025-59854
- EPSS 0.12%
- Veröffentlicht 06.05.2026 10:27:08
- Zuletzt bearbeitet 07.10.2026 09:10:00
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security ...