CVE-2025-59854: Hcltech Dfxanalytics
Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security Policy (CSP).
Affected products
- Hcltech Dfxanalytics: before 4.1 (fixed in 4.1)
Published 2026-05-06. Last modified 2026-10-07.