Impact
The vulnerability in HCL DFXAnalytics allows an attacker to view internal file paths through unhandled error messages, system logs, or debugging output. By exposing the directory structure, an attacker obtains information that can be used to map the server environment and identify further vectors for exploitation. This is an information‑disclosure flaw classified as CWE‑200, potentially compromising confidentiality of system configuration.
Affected Systems
This issue affects installations of HCL Software's DFXAnalytics product. No specific product version information is provided, so all deployed instances remain vulnerable until a vendor‑released fix is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is less than 1%. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation via the application’s dashboard or error endpoints, wherein an attacker can trigger or observe error handling paths that reveal file system information.
OpenCVE Enrichment