HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security Policy (CSP).
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 06 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security Policy (CSP). | |
| Title | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-05-06T10:27:08.190Z
Reserved: 2025-09-22T14:59:58.052Z
Link: CVE-2025-59854
No data.
Status : Received
Published: 2026-05-06T11:16:04.810
Modified: 2026-05-06T11:16:04.810
Link: CVE-2025-59854
No data.
OpenCVE Enrichment
No data.
Weaknesses