Executive brief
HCL DFXAnalytics, a data analytics platform, is missing a standard security configuration that ensures web browsers only connect using encrypted channels. This flaw could allow an attacker on the same network to intercept or manipulate user traffic by forcing the connection to use an unencrypted format. While the risk is low, it could lead to the exposure of sensitive session information during a man-in-the-middle attack.
Technical details
HCL DFXAnalytics fails to implement the HTTP Strict Transport Security (HSTS) policy in its web responses. This missing 'Strict-Transport-Security' header allows a remote attacker with network access to perform a protocol downgrade attack (SSL stripping). By forcing the application to communicate over unencrypted HTTP, the attacker can conduct man-in-the-middle (MitM) attacks to intercept or modify traffic. The vulnerability is present in version 3.0 and below and requires the attacker to be in a position to intercept network traffic. Remediation involves configuring the web server to include the HSTS header in all responses.
Affected products
- HCL Software DFXAnalytics 3.0 and below
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory