CVE-2025-59853
Estado: AnalizadaMedia (5.3)—
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-209
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-59853",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-59853",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-06T12:29:02.256404Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.1,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@hcl.com",
"affectedData": [
{
"vendor": "HCL",
"product": "DFXAnalytics",
"versions": [
{
"status": "affected",
"version": "3.1 and below"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-06T11:16:04.683",
"references": [
{
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130569",
"tags": [
"Vendor Advisory"
],
"source": "psirt@hcl.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"description": [
{
"lang": "en",
"value": "CWE-209"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations."
},
{
"lang": "es",
"value": "HCL DFXAnalytics se ve afectado por una vulnerabilidad de manejo de errores inadecuado donde la aplicación expone trazas de pila detalladas en las respuestas, lo que podría permitir a un atacante obtener información sobre la estructura interna de la aplicación, la lógica del código y las configuraciones del entorno."
}
],
"lastModified": "2026-09-30T22:10:00.273",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:dfxanalytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBC416E1-5496-4734-AE0E-8AA575A69D18",
"versionEndExcluding": "4.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@hcl.com"
}