HCL DFXServer Unencrypted Communication Vulnerability

Vulnerability

A vulnerability allowing unencrypted communication has been identified in HCL DFXServer versions 2.5 and below. The application allows users to connect over unencrypted HTTP channels, potentially enabling remote attackers to intercept network traffic and access sensitive data exchanged between users and the application.

Impact

Exploitation of this vulnerability could lead to interception of network traffic, allowing exposure of sensitive data transmitted between the user and the application.

Remediation

Users can upgrade to HCL DFXServer version 3.2, where this vulnerability has been addressed.

Added: Jul 16, 2026, 12:27 PM
Updated: Jul 16, 2026, 12:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.0
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.