HCL DFXServer Missing Access Control Vulnerability

Vulnerability

A missing access control vulnerability has been identified in HCL DFXServer versions 2.5 and below. Certain endpoints can be accessed without authentication, allowing any network user to invoke these APIs and interact with the application without verifying their identity or authorization level.

Impact

Exploitation of this vulnerability allows unauthorized users to access and interact with the application through the exposed APIs, bypassing authentication and authorization checks.

Remediation

Users can upgrade to HCL DFXServer version 3.2, where this vulnerability has been successfully mitigated.

Added: Jul 16, 2026, 12:24 PM
Updated: Jul 16, 2026, 12:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
7.4
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.