Description
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.
Published: 2026-07-16
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows a remote attacker to extract internal IP address details from the server’s responses, revealing the organization’s network topology. The disclosed information does not grant direct code execution or privilege escalation, but it can aid an attacker in mapping the internal infrastructure and planning more focused attacks, such as credential harvesting or lateral movement. The weakness is classified as CWE‑200, denoting sensitive data exposure without proper protection.

Affected Systems

HCL Software’s DFXAnalytics is affected; no version range is specified, implying that all current installations may be vulnerable until a vendor fix is issued.

Risk and Exploitability

The CVSS score of 2.6 classifies the issue as low severity, and the EPSS score of <1 % indicates a very small likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker accessing the application’s HTTP responses—either through unauthenticated requests or by leveraging an existing authenticated session. The exposure is a result of insufficient response sanitization and lack of network segmentation.

Generated by OpenCVE AI on July 31, 2026 at 01:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch for HCL DFXAnalytics as soon as it is released.
  • Restrict access to the application so that only authenticated, authorized users from trusted networks can retrieve pages or endpoints that expose internal network details.
  • Configure the application to remove or obfuscate internal IP addresses from any HTML or API responses that could be viewed by external users.

Generated by OpenCVE AI on July 31, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech dfxanalytics
Vendors & Products Hcltech
Hcltech dfxanalytics

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.
Title HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

Hcltech Dfxanalytics
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-16T14:14:51.156Z

Reserved: 2026-04-01T16:32:01.021Z

Link: CVE-2026-35142

cve-icon Vulnrichment

Updated: 2026-07-16T14:14:47.333Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor