HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation.
CVSS Score
5.3
MEDIUM
Published
16 Jul 2026 14:16
Modified
17 Jul 2026 19:11
Vendor
Hcltech
Product
Dfxanalytics
Source
CIRCL
CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Complexity
Low
Privileges
None
Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Weaknesses (CWE)
CWE-200
References
Affected Systems
Hcltech
Dfxanalytics
Hcltech
Dfx Server
Dfxanalytics
External Links
KEV Status
Not in CISA KEV catalog