CyberRota Analysis
AI-GeneratedHCL DFXAnalytics is vulnerable due to the absence of the "secure" attribute on session cookies generated during authentication, potentially exposing sensitive data to interception by remote attackers. This flaw could allow attackers to capture session tokens and credentials transmitted over unencrypted channels. Organizations using HCL DFXAnalytics should prioritize addressing this vulnerability to mitigate the risk of credential theft and session hijacking.
Original NVD Description
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.
Related CVEs
Other vulnerabilities affecting the same vendor(s)