Impact
HCL DFXAnalytics fails to mark session cookies with the secure attribute during authentication. Without this flag, cookies can be transmitted over plain HTTP connections and captured by an attacker monitoring network traffic. The exposed cookies may contain session identifiers or credentials, allowing an adversary to hijack sessions or retrieve user credentials, thereby compromising confidentiality and potentially gaining unauthorized access.
Affected Systems
The affected product is HCL DFXAnalytics provided by HCL Software. No specific version information is supplied, so all installations of HCL DFXAnalytics should be examined for the missing secure flag on session cookies.
Risk and Exploitability
The CVSS score of 3 indicates low severity, and the EPSS score is less than 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no current widespread exploitation. Nonetheless, the attack vector is fairly simple: an attacker who can eavesdrop on HTTP traffic can intercept cookies. While the risk is moderate given the low score, the potential impact of credential theft warrants updating the system.
OpenCVE Enrichment