Executive brief
HCL DFXAnalytics, a data analytics platform, is affected by a security flaw that reveals internal network IP addresses in its server responses. While this does not directly allow an attacker to steal data or crash the system, it provides them with a map of the internal corporate network. This information can be used by sophisticated actors to plan more complex, targeted attacks against other internal systems.
Technical details
HCL DFXAnalytics (version 3.0 and below) is vulnerable to information disclosure (CWE-200) due to the inclusion of internal IP addresses within generated server responses. This is a network-based vulnerability, though the CVSS vector suggests high complexity and high privileges are required for exploitation. An attacker can leverage this leaked metadata to perform reconnaissance and map the internal network topology. This information facilitates lateral movement or targeted attacks against internal infrastructure that is otherwise hidden from the external network. Users are advised to consult HCL security bulletin KB0131787 for remediation steps.
Affected products
- HCL Software DFXAnalytics 3.0 and below
Timeline
- 2026-07-16: advisory: NVD and HCL Software published the vulnerability details.