3.1
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Description
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security Policy (CSP).
Basic Information
ID
CVE-2025-59854
Source
HCL
Published
May 6, 2026 at 10:27
Affected Product
Vendor
HCL
Product
DFXAnalytics
Version
3.1 and below
Affected Versions
HCL DFXAnalytics 3.1 and below