HCL DFXAnalytics
- <= 3.0
A vulnerability allowing account takeover through response manipulation has been identified in HCL DFXAnalytics versions 3.0 and below. This issue arises from the application's failure to properly secure HTTP responses, enabling remote attackers to intercept and modify response contents before they reach the client. By doing so, attackers can manipulate authentication or authorization processes, bypassing controls and gaining unauthorized access to user accounts.
Exploitation of this vulnerability could lead to unauthorized access to user accounts by manipulating authentication or authorization responses.
Users can upgrade to HCL DFXAnalytics Version 4.1, where this vulnerability has been successfully mitigated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.