HCL DFXAnalytics Missing Secure Attribute in SSL Cookie Vulnerability

Vulnerability

A vulnerability exists in HCL DFXAnalytics versions 3.0 and below, where the application does not set the 'secure' attribute on session cookies during authentication. This oversight could enable remote attackers to intercept network traffic and capture sensitive cookies, session tokens, or credentials transmitted in cleartext over unencrypted channels.

Impact

Exploitation of this vulnerability could lead to interception of session cookies or credentials, allowing for unauthorized access or session hijacking.

Remediation

Users can upgrade to HCL DFXAnalytics version 4.1, where this vulnerability has been addressed.

Added: Jul 16, 2026, 2:39 PM
Updated: Jul 16, 2026, 2:39 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.0
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.