Impact
The missing access control flaw (CWE-284) in HCL DFXServer allows users to access certain API endpoints without authentication. Because these endpoints can be reached from any browser connected to the network, an attacker can invoke them and interact with the application without being verified. This can lead to unauthorized operations, potentially exposing sensitive information or altering configuration.
Affected Systems
HCL Software’s DFXServer application is impacted. The affected versions are not explicitly listed; all released versions of DFXServer appear vulnerable.
Risk and Exploitability
The flaw has a CVSS score of 6.3, indicating moderate severity. One of the endpoints is exposed to any network user through a standard browser. The EPSS score is less than 1%, indicating a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. However, the lack of authentication means that attackers with network access could abuse the endpoints quickly.
OpenCVE Enrichment