Impact
The flaw exposes HCL DFXAnalytics to a remote attacker who can intercept and modify the HTTP responses sent from the server before they reach the client application. By tampering with the response payload, the attacker can alter authentication or authorization logic, thereby bypassing account controls and gaining unauthorized access to targeted user accounts. This enables the compromise of user data confidentiality and integrity and is classified as CWE-294.
Affected Systems
The weakness affects HCL Software’s DFXAnalytics product. No specific version information is available, so any deployed instance of DFXAnalytics could be impacted until further details are released.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of <1% suggests a very low likelihood of exploitation and the flaw is not listed in CISA KEV. The attack is remote over the network, requiring an attacker to position themselves to intercept or modify traffic between the DFXAnalytics server and client. In environments where HTTP traffic can be monitored or altered—such as unencrypted connections or poorly segmented networks—the vulnerability could be exploited, making timely patching advisable.
OpenCVE Enrichment