Executive brief
HCL DFXServer is affected by a security flaw where certain administrative or data endpoints do not require a password to access. This allows unauthorized individuals on the network to interact with the application and potentially view or modify data without any identity verification. The issue could lead to unauthorized access to sensitive business functions or information managed by the server.
Technical details
A missing access control vulnerability (CWE-284) exists in HCL DFXServer version 2.5 and below. The flaw resides in specific API endpoints that fail to enforce authentication requirements, allowing them to be reached by unauthenticated network users. While the CVSS vector indicates a requirement for user interaction (UI:R), an attacker can successfully invoke these APIs to interact with the application's backend without valid credentials. This can result in a partial loss of confidentiality, integrity, and availability. Users are advised to review HCL security bulletin KB0131782 for remediation steps.
Affected products
- HCL Software DFXServer 2.5 and below
Timeline
- 2026-07-16: advisory
- 2026-07-16: disclosed