HCL / DFXAnalytics
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-59866 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables… | LOW | 3.3 | Jul 17, 2026 |
| CVE-2026-56456 | HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. | MEDIUM | 5.3 | Jul 16, 2026 |
| CVE-2026-56455 | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). | HIGH | 7.5 | Jul 16, 2026 |
| CVE-2026-56454 | HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. | HIGH | 7.5 | Jul 16, 2026 |
| CVE-2026-56453 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. | CRITICAL | 9.8 | Jul 16, 2026 |
| CVE-2026-35145 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. | LOW | 3.1 | Jul 16, 2026 |
| CVE-2026-35143 | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. | MEDIUM | 6.5 | Jul 16, 2026 |
| CVE-2026-35142 | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. | HIGH | 8.2 | Jul 16, 2026 |
| CVE-2026-35141 | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability | MEDIUM | 5.3 | Jul 16, 2026 |
| CVE-2026-35140 | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability | HIGH | 7.2 | Jul 16, 2026 |
| CVE-2025-59854 | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability | MEDIUM | 6.1 | May 6, 2026 |
| CVE-2025-59853 | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability | MEDIUM | 5.3 | May 6, 2026 |
| CVE-2025-59852 | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability | CRITICAL | 9.1 | May 6, 2026 |
| CVE-2025-59851 | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability | CRITICAL | 9.8 | May 6, 2026 |
| CVE-2025-31970 | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability | MEDIUM | 6.1 | May 6, 2026 |
Showing 1 to 15 of 15 CVEs