HCL DFXAnalytics Insecure Security Header Configuration Vulnerability
Vulnerability
A vulnerability exists in HCL DFXAnalytics versions through 3.1, related to insecure security header configuration. The application uses the outdated X-XSS-Protection header, which could enable an attacker to exploit browser-specific rendering issues or bypass security measures that should be enforced by a strong Content Security Policy (CSP).
Impact
Exploitation of this vulnerability could lead to bypassing of security controls intended to be managed by the Content Security Policy, potentially allowing for Cross-Site Scripting (XSS) attacks.
Remediation
Users are advised to upgrade to HCL DFXAnalytics version 4.1.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
