Executive brief
HCL DFXAnalytics, a data analytics platform, is vulnerable to a login replay attack. This flaw allows a remote attacker to capture and reuse valid login information to gain unauthorized access to the system. While the risk is rated as low due to the complexity of the attack, it could potentially allow an attacker to impersonate a legitimate user and perform unauthorized actions within the application.
Technical details
HCL DFXAnalytics versions 3.0 and below are vulnerable to a login replay attack (CWE-294). The application fails to sufficiently validate the uniqueness or timeliness of authentication messages, allowing a remote attacker to intercept and retransmit valid authentication data. Exploitation requires high privileges and user interaction under specific network conditions (high attack complexity). To remediate this, the vendor recommends implementing a mechanism to include timestamps with every message so that the recipient system can reject messages exceeding a specific age threshold.
Affected products
- HCL Software DFXAnalytics 3.0 and below
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory