HCL DFXAnalytics
- <= 3.0
A vulnerability exists in HCL DFXAnalytics versions 3.0 and below, where the application does not set the 'secure' attribute on session cookies during authentication. This oversight could enable remote attackers to intercept network traffic and capture sensitive cookies, session tokens, or credentials transmitted in cleartext over unencrypted channels.
Exploitation of this vulnerability could lead to interception of session cookies or credentials, allowing for unauthorized access or session hijacking.
Users can upgrade to HCL DFXAnalytics version 4.1, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.