Insecure Security Header Configuration in HCL DFXAnalytics
CVE-2025-31970

5.3MEDIUM

Key Information:

Vendor
CVE Published:
6 May 2026

What is CVE-2025-31970?

HCL DFXAnalytics is compromised due to an insecure security header configuration. The lack of strict directives for the Content-Security-Policy regarding object-src and base-uri makes the application susceptible to various injection vectors, including Cross-Site Scripting (XSS). This vulnerability can potentially allow attackers to exploit the application, leading to unauthorized access and data compromise.

Affected Version(s)

DFXAnalytics 3.1 and below

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.