HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.
CVSS Score
5.5
MEDIUM
Published
16 Jul 2026 14:16
Modified
17 Jul 2026 19:09
Vendor
Hcltech
Product
Dfxanalytics
Source
CIRCL
CVSS v3 Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Vector
Network
Complexity
High
Privileges
Low
Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Weaknesses (CWE)
CWE-294
References
Affected Systems
Hcltech
Dfxanalytics
Hcltech
Dfx Server
Dfxanalytics
External Links
KEV Status
Not in CISA KEV catalog