HCL DFXAnalytics
- <= 3.0
An internal file path disclosure vulnerability has been identified in HCL DFXAnalytics version 3.0 and below. This vulnerability arises because the application dashboard unintentionally reveals sensitive information about its internal file structure and directory paths. This leakage occurs through unhandled error messages, system logs, or debugging output. As a result, a remote attacker could potentially map the underlying server environment and identify targets for further exploitation.
Exploitation of this vulnerability could lead to unauthorized mapping of the server environment, allowing attackers to identify and target specific areas for exploitation.
Users can upgrade to HCL DFXAnalytics version 4.1, where this vulnerability has been successfully mitigated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.