HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.
References
Link | Resource |
---|---|
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 | Vendor Advisory |
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:36
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.3 |
References | () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 - Vendor Advisory |
09 Jan 2024, 17:58
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:hcltech:dryice_myxalytics:6.1:*:*:*:*:*:*:* cpe:2.3:a:hcltech:dryice_myxalytics:5.9:*:*:*:*:*:*:* cpe:2.3:a:hcltech:dryice_myxalytics:6.0:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CWE | NVD-CWE-Other | |
First Time |
Hcltech dryice Myxalytics
Hcltech |
|
References | () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 - Vendor Advisory |
03 Jan 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-03 03:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-50343
Mitre link : CVE-2023-50343
CVE.ORG link : CVE-2023-50343
JSON object : View
Products Affected
hcltech
- dryice_myxalytics
CWE