HCL DFXAnalytics Insecure Security Header Configuration Vulnerability

Vulnerability

A vulnerability exists in HCL DFXAnalytics versions through 3.1, related to insecure security header configuration. The application uses the outdated X-XSS-Protection header, which could enable an attacker to exploit browser-specific rendering issues or bypass security measures that should be enforced by a strong Content Security Policy (CSP).

Impact

Exploitation of this vulnerability could lead to bypassing of security controls intended to be managed by the Content Security Policy, potentially allowing for Cross-Site Scripting (XSS) attacks.

Remediation

Users are advised to upgrade to HCL DFXAnalytics version 4.1.

Added: May 6, 2026, 11:28 AM
Updated: May 6, 2026, 11:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.0
remediation
0.0
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.