HCL DFXAnalytics
- <= 3.0
A vulnerability exists in HCL DFXAnalytics versions through 3.0, where the application does not implement the HTTP Strict Transport Security (HSTS) policy in its responses. This omission could enable a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP), potentially leading to man-in-the-middle (MitM) attacks.
The lack of HSTS can allow attackers to intercept and manipulate communications, downgrading security to unencrypted HTTP and increasing the risk of MitM attacks.
Users can upgrade to HCL DFXAnalytics version 4.1, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.