HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-16 14:16
Updated : 2026-07-17 16:44
NVD link : CVE-2026-35141
Mitre link : CVE-2026-35141
CVE.ORG link : CVE-2026-35141
JSON object : View
Products Affected
hcltech
- dfxanalytics
CWE
CWE-294
Authentication Bypass by Capture-replay
