Description
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.
Published: 2026-07-16
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a remote attacker to force the application to fall back to an unencrypted HTTP channel when the server does not send an HTTP Strict‑Transport‑Security header. This omission can enable a man‑in‑the‑middle attack, compromising confidentiality and integrity of data transmitted to and from HCL DFXAnalytics. The weakness is categorized as a disclosure of information (CWE‑200).

Affected Systems

Vendor: HCL Software. Product: DFXAnalytics. All deployments of DFXAnalytics that lack an HSTS header are affected; no specific version range is provided.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity. EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. If traffic to the application can be observed, an attacker could exploit the missing header to downgrade secure connections and conduct MitM attacks. However, the absence of a currently active exploit or broader impact keeps the immediate threat modest.

Generated by OpenCVE AI on July 31, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HCL DFXAnalytics by following the KB article linked in the reference, adding the 'Strict-Transport-Security' header to all web responses.
  • Reconfigure the web server (IIS, Apache, Nginx, etc.) to redirect all HTTP requests to HTTPS and enable the HSTS directive so that clients automatically enforce secure connections.
  • Deploy the changes and restart the application and web server to apply the updated configuration.

Generated by OpenCVE AI on July 31, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech dfxanalytics
Vendors & Products Hcltech
Hcltech dfxanalytics

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.
Title HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Hcltech Dfxanalytics
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-16T13:45:02.414Z

Reserved: 2026-04-01T16:32:01.021Z

Link: CVE-2026-35145

cve-icon Vulnrichment

Updated: 2026-07-16T13:44:59.011Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor