HCL DFXServer
- <= 2.5
A missing access control vulnerability has been identified in HCL DFXServer versions 2.5 and below. Certain endpoints can be accessed without authentication, allowing any network user to invoke these APIs and interact with the application without verifying their identity or authorization level.
Exploitation of this vulnerability allows unauthorized users to access and interact with the application through the exposed APIs, bypassing authentication and authorization checks.
Users can upgrade to HCL DFXServer version 3.2, where this vulnerability has been successfully mitigated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.