Impact
The flaw allows a remote attacker to extract internal IP address details from the server’s responses, revealing the organization’s network topology. The disclosed information does not grant direct code execution or privilege escalation, but it can aid an attacker in mapping the internal infrastructure and planning more focused attacks, such as credential harvesting or lateral movement. The weakness is classified as CWE‑200, denoting sensitive data exposure without proper protection.
Affected Systems
HCL Software’s DFXAnalytics is affected; no version range is specified, implying that all current installations may be vulnerable until a vendor fix is issued.
Risk and Exploitability
The CVSS score of 2.6 classifies the issue as low severity, and the EPSS score of <1 % indicates a very small likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker accessing the application’s HTTP responses—either through unauthenticated requests or by leveraging an existing authenticated session. The exposure is a result of insufficient response sanitization and lack of network segmentation.
OpenCVE Enrichment