Impact
The vulnerability allows a remote attacker to force the application to fall back to an unencrypted HTTP channel when the server does not send an HTTP Strict‑Transport‑Security header. This omission can enable a man‑in‑the‑middle attack, compromising confidentiality and integrity of data transmitted to and from HCL DFXAnalytics. The weakness is categorized as a disclosure of information (CWE‑200).
Affected Systems
Vendor: HCL Software. Product: DFXAnalytics. All deployments of DFXAnalytics that lack an HSTS header are affected; no specific version range is provided.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity. EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. If traffic to the application can be observed, an attacker could exploit the missing header to downgrade secure connections and conduct MitM attacks. However, the absence of a currently active exploit or broader impact keeps the immediate threat modest.
OpenCVE Enrichment