Executive brief
HCL DFXServer is vulnerable to a security flaw that allows unauthorized individuals to access its internal programming interfaces without a password. This could allow an attacker to view sensitive information or perform unauthorized actions within the system, potentially compromising business data and operational integrity. The issue affects all versions of the software up to and including version 2.5.
Technical details
HCL DFXServer (versions 2.5 and below) contains a broken authentication vulnerability (CWE-639) within its API implementation. The application fails to properly validate the authentication status of users when they attempt to access specific API endpoints directly. A remote, unauthenticated attacker can exploit this by sending crafted network requests to these endpoints, bypassing security controls to interact with the API. This can lead to unauthorized data retrieval (High Confidentiality impact) and limited unauthorized modifications (Low Integrity impact). The vulnerability is exploitable over the network without user interaction.
Affected products
- HCL Software DFXServer 2.5 and below
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory