Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability
Vulnerability Description
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
不恰当实现的标准安全检查
Vulnerability Title
HCL DFXAnalytics 跨站脚本漏洞
Vulnerability Description
HCL DFXAnalytics是印度HCL公司的一个软件交付与运维数据分析平台。 HCL DFXAnalytics存在跨站脚本漏洞,该漏洞源于不安全的Security Header配置,Content-Security-Policy未为object-src和base-uri定义严格指令,可能允许攻击者利用注入向量,如跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A