Executive brief
HCL DFXAnalytics, a data analytics platform, contains a security flaw where session cookies are not properly configured to prevent unauthorized cross-site requests. If a logged-in user visits a malicious website, an attacker could potentially perform actions on the user's behalf within the DFXAnalytics application. This risk is primarily present if the application lacks other standard defenses like anti-forgery tokens.
Technical details
HCL DFXAnalytics fails to set the 'SameSite' attribute on session cookies generated during the authentication process. This omission allows the browser to send the session cookie during cross-site requests, creating a vulnerability to Cross-Site Request Forgery (CSRF). An attacker could exploit this by tricking an authenticated user into visiting a malicious site that triggers unauthorized requests to the DFXAnalytics application. The impact is mitigated if the application implements secondary defenses such as Anti-CSRF tokens. The vulnerability affects version 3.0 and below.
Affected products
- HCL Software DFXAnalytics 3.0 and below
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory