HCL DFXAnalytics Missing HTTP Strict-Transport-Security Header Vulnerability

Vulnerability

A vulnerability exists in HCL DFXAnalytics versions through 3.0, where the application does not implement the HTTP Strict Transport Security (HSTS) policy in its responses. This omission could enable a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP), potentially leading to man-in-the-middle (MitM) attacks.

Impact

The lack of HSTS can allow attackers to intercept and manipulate communications, downgrading security to unencrypted HTTP and increasing the risk of MitM attacks.

Remediation

Users can upgrade to HCL DFXAnalytics version 4.1, where this vulnerability has been addressed.

Added: Jul 16, 2026, 2:31 PM
Updated: Jul 16, 2026, 2:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.2
exploitability
6.0
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.