Junglewise Threat Intelligence

CVE-2026-35145: HCL DFXAnalytics missing HSTS header

CVE-2026-35145 · Severity: low · CVSS 3.1 · Published 2026-07-16

Technologies: HCL Software DFXAnalytics. Vendors: HCL Software.

Executive brief

HCL DFXAnalytics, a data analytics platform, is missing a standard security configuration that ensures web browsers only connect using encrypted channels. This flaw could allow an attacker on the same network to intercept or manipulate user traffic by forcing the connection to use an unencrypted format. While the risk is low, it could lead to the exposure of sensitive session information during a man-in-the-middle attack.

Technical details

HCL DFXAnalytics fails to implement the HTTP Strict Transport Security (HSTS) policy in its web responses. This missing 'Strict-Transport-Security' header allows a remote attacker with network access to perform a protocol downgrade attack (SSL stripping). By forcing the application to communicate over unencrypted HTTP, the attacker can conduct man-in-the-middle (MitM) attacks to intercept or modify traffic. The vulnerability is present in version 3.0 and below and requires the attacker to be in a position to intercept network traffic. Remediation involves configuring the web server to include the HSTS header in all responses.

Affected products

  • HCL Software DFXAnalytics 3.0 and below

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats