HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.
Weakness
The product does not properly verify that the source of data or communication is valid.