Description
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security Policy (CSP).
Published: 2026-05-06
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL DFXAnalytics suffers from an insecure security header configuration. The application still sends the obsolete X‑XSS‑Protection header, which does not prevent modern browser‑based rendering flaws or allow cross‑site scripting injection in the absence of a proper Content Security Policy. This weakness can enable an attacker to deliver malicious scripts that execute in a victim’s browser, compromising confidentiality, integrity, or availability of web content.

Affected Systems

The affected product is HCL DFXAnalytics. No specific version range is provided in the CNA data, so all deployments using this product should be inspected for the legacy X‑XSS‑Protection header and for the presence of a CSP header. The vulnerability is vendor‑specific to HCL DFXAnalytics and does not affect other HCL or third‑party applications.

Risk and Exploitability

The CVSS score of 3.1 classifies this issue as low‑severity, and the EPSS score of 0.00029 indicates a very low probability that this vulnerability will be actively exploited. The vulnerability has not been listed in the CISA KEV catalog. Exploitation requires a web‑application user to interact with a crafted page that triggers the fallback behavior of the obsolete header or to supply input that the application renders unsanitized. Based on the description, the likely attack vector is local to the web browser, meaning that a user visiting a malicious page could trigger the flaw without additional authentication. The risk remains low, though missing security controls could be leveraged for XSS attacks.

Generated by OpenCVE AI on May 7, 2026 at 22:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Remove the X‑XSS‑Protection header from all HTTP responses.
  • Implement a robust Content Security Policy header that explicitly whitelists trusted sources.
  • Verify that the CSP is correctly applied on every page and test it with security scanners.

Generated by OpenCVE AI on May 7, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcl
Hcl dfxanalytics
Vendors & Products Hcl
Hcl dfxanalytics

Thu, 07 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech dfxanalytics
Weaknesses CWE-79
CPEs cpe:2.3:a:hcltech:dfxanalytics:*:*:*:*:*:*:*:*
Vendors & Products Hcltech
Hcltech dfxanalytics

Wed, 06 May 2026 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 10:45:00 +0000

Type Values Removed Values Added
Description HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security Policy (CSP).
Title HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcl Dfxanalytics
Hcltech Dfxanalytics
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-05-06T12:04:16.597Z

Reserved: 2025-09-22T14:59:58.052Z

Link: CVE-2025-59854

cve-icon Vulnrichment

Updated: 2026-05-06T12:04:12.943Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T11:16:04.810

Modified: 2026-05-07T20:02:54.710

Link: CVE-2025-59854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T22:15:06Z

Weaknesses