HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.
References
Link | Resource |
---|---|
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 | Vendor Advisory |
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.3 |
09 Jan 2024, 17:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 - Vendor Advisory | |
First Time |
Hcltech dryice Myxalytics
Hcltech |
|
CWE | NVD-CWE-Other | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CPE | cpe:2.3:a:hcltech:dryice_myxalytics:6.1:*:*:*:*:*:*:* cpe:2.3:a:hcltech:dryice_myxalytics:5.9:*:*:*:*:*:*:* cpe:2.3:a:hcltech:dryice_myxalytics:6.0:*:*:*:*:*:*:* |
03 Jan 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-03 03:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-50343
Mitre link : CVE-2023-50343
CVE.ORG link : CVE-2023-50343
JSON object : View
Products Affected
hcltech
- dryice_myxalytics
CWE