CVE-2026-56454: HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update HCL DFXAnalytics TLS configuration to disable all support for TLS 1.0 and TLS 1.1, and exclusively enable secure protocols TLS 1.2 and TLS 1.3.
HCL DFXAnalytics TLS protocol support = Disable TLS 1.0 and TLS 1.1; enable only TLS 1.2 and TLS 1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56454?
The severity of CVE-2026-56454 is rated as medium with a score of 5.9.
How do I fix CVE-2026-56454?
To fix CVE-2026-56454, you need to disable all support for TLS 1.0 and TLS 1.1 in HCL DFXAnalytics.
What systems are affected by CVE-2026-56454?
CVE-2026-56454 affects the HCL DFXAnalytics application.
What type of vulnerability is CVE-2026-56454?
CVE-2026-56454 is classified as a Deprecated Protocol vulnerability.
What risks are associated with CVE-2026-56454?
CVE-2026-56454 poses risks of data interception and decryption due to the use of outdated TLS protocols.