HCL DFXAnalytics Missing SameSite Attribute Vulnerability Allowing Cross-Site Request Forgery

Vulnerability

A vulnerability exists in HCL DFXAnalytics versions through 3.0, where the application does not set the 'SameSite' attribute on session cookies during authentication. This oversight could enable remote attackers to perform Cross-Site Request Forgery (CSRF) attacks, particularly if additional protections like Anti-CSRF tokens are not in place.

Impact

Exploitation of this vulnerability could lead to Cross-Site Request Forgery (CSRF) attacks, allowing attackers to perform actions on behalf of authenticated users without their consent.

Remediation

Users can upgrade to HCL DFXAnalytics version 4.1, where this vulnerability has been addressed.

Added: Jul 16, 2026, 2:34 PM
Updated: Jul 16, 2026, 2:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.6
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.