HCL DFXServer
- <= 2.5
A broken authentication vulnerability has been identified in HCL DFXServer versions 2.5 and below. This vulnerability allows unauthenticated attackers to access specific API endpoints without valid credentials. The application fails to properly verify user authentication status, enabling unauthorized interactions with the APIs and the execution of unauthorized actions.
Exploitation of this vulnerability allows for authentication bypass, granting unauthorized access to the application and its functionalities via the affected APIs.
Users can upgrade to HCL DFXServer version 3.2, where this vulnerability has been successfully mitigated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.