HCL DFXAnalytics是印度HCL公司的中间件。 HCL DFXAnalytics 3.0及之前版本存在授权问题漏洞,该漏洞源于响应操纵问题,可能导致远程攻击者通过拦截和修改服务器HTTP响应内容,操纵身份验证或授权逻辑,绕过控制并获取对目标用户账户的未授权访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL Software | DFXAnalytics | version 3.0 and below |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | DFXAnalytics | version 3.0 and below | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35147 | 8.2 HIGH | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. |
| CVE-2026-35149 | 8.2 HIGH | HCL DFXServer is affected by an Authentication Bypass vulnerability via server response ma |
| CVE-2026-35148 | 6.3 MEDIUM | HCL DFXServer is affected by a Missing Access Control vulnerability |
| CVE-2026-56454 | 5.9 MEDIUM | HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS |
| CVE-2026-56456 | 5.3 MEDIUM | HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. |
| CVE-2026-56455 | 5.3 MEDIUM | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial |
| CVE-2026-35145 | 3.1 LOW | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerabil |
| CVE-2026-35143 | 3.0 LOW | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. |
| CVE-2026-35140 | 3.0 LOW | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cook |
| CVE-2026-35142 | 2.6 LOW | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. |
| CVE-2026-35141 | 2.6 LOW | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability |
No comments yet