CVE-2026-35145: HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify HCL DFXAnalytics to add the HTTP Strict Transport Security (HSTS) header ("Strict-Transport-Security") to every web application HTTP response so clients are forced to use HTTPS and cannot be downgraded to HTTP for MitM attacks.
HCL DFXAnalytics web application responses HTTP response header: Strict-Transport-Security = Include the "Strict-Transport-Security" header in all web application responses
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35145?
The severity of CVE-2026-35145 is classified as low with a score of 3.1.
How do I fix CVE-2026-35145?
To fix CVE-2026-35145, implement the HTTP Strict Transport Security (HSTS) header in the responses from HCL DFXAnalytics.
What type of vulnerability is CVE-2026-35145?
CVE-2026-35145 is a Missing HTTP Strict-Transport-Security Header vulnerability.
What impact does CVE-2026-35145 have?
CVE-2026-35145 could allow a remote attacker to downgrade the communication channel to an unencrypted connection.
Which software is affected by CVE-2026-35145?
CVE-2026-35145 affects HCL DFXAnalytics.