HCL DFXServer Broken Authentication Vulnerability via Direct API Access

Vulnerability

A broken authentication vulnerability has been identified in HCL DFXServer versions 2.5 and below. This vulnerability allows unauthenticated attackers to access specific API endpoints without valid credentials. The application fails to properly verify user authentication status, enabling unauthorized interactions with the APIs and the execution of unauthorized actions.

Impact

Exploitation of this vulnerability allows for authentication bypass, granting unauthorized access to the application and its functionalities via the affected APIs.

Remediation

Users can upgrade to HCL DFXServer version 3.2, where this vulnerability has been successfully mitigated.

Added: Jul 16, 2026, 12:26 PM
Updated: Jul 16, 2026, 12:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.