Insecure Security Header Configuration in HCL DFXAnalytics
CVE-2025-59854

3.1LOW

Key Information:

Vendor
CVE Published:
6 May 2026

What is CVE-2025-59854?

HCL DFXAnalytics contains a vulnerability in its security header configuration, specifically concerning the outdated X-XSS-Protection header. This flaw poses a risk by potentially allowing attackers to exploit issues in browser-specific rendering, effectively bypassing essential security measures that should be enforced by a comprehensive Content Security Policy (CSP). Organizations using HCL DFXAnalytics should prioritize assessing and mitigating this vulnerability to enhance their overall security posture.

Affected Version(s)

DFXAnalytics 3.1 and below

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.