SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-35145

LOW · CVSS 3.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

HCL DFXAnalytics is vulnerable due to the absence of the HTTP Strict Transport Security (HSTS) header, which could enable remote attackers to downgrade secure connections to unencrypted HTTP, facilitating man-in-the-middle (MitM) attacks. Organizations utilizing this application should prioritize remediation by implementing the HSTS policy in their web responses to enhance security against potential data interception. While the severity is classified as low, the risk of exposure to sensitive information warrants attention, especially for environments handling confidential data.

CVE
CVE-2026-35145
Severity
LOW
CVSS
3.1
EPSS
0.17%

Original NVD Description

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.

Related CVEs

Other vulnerabilities affecting the same vendor(s)