Insecure Security Header Configuration in HCL DFXAnalytics
CVE-2025-31970
5.3MEDIUM
What is CVE-2025-31970?
HCL DFXAnalytics is compromised due to an insecure security header configuration. The lack of strict directives for the Content-Security-Policy regarding object-src and base-uri makes the application susceptible to various injection vectors, including Cross-Site Scripting (XSS). This vulnerability can potentially allow attackers to exploit the application, leading to unauthorized access and data compromise.
Affected Version(s)
DFXAnalytics 3.1 and below