HCL DFXAnalytics
- <= 3.0
A vulnerability exists in HCL DFXAnalytics versions through 3.0, where the application does not set the 'SameSite' attribute on session cookies during authentication. This oversight could enable remote attackers to perform Cross-Site Request Forgery (CSRF) attacks, particularly if additional protections like Anti-CSRF tokens are not in place.
Exploitation of this vulnerability could lead to Cross-Site Request Forgery (CSRF) attacks, allowing attackers to perform actions on behalf of authenticated users without their consent.
Users can upgrade to HCL DFXAnalytics version 4.1, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.