Session Fixation Vulnerability in HCL MyXalytics Platform
CVE-2024-42170

6.8MEDIUM

Key Information:

Vendor
HCL Software Software
Status
Dryice Myxalytics
Vendor
CVE Published:
11 January 2025

Summary

HCL MyXalytics is susceptible to a session fixation vulnerability, allowing cyber criminals to exploit this flaw by sending specially crafted URLs that include a session token. If a victim unwittingly clicks such a link, an attacker can hijack the user's login session, potentially gaining unauthorized access to sensitive information. This poses a significant risk to user data security, necessitating prompt awareness and mitigation strategies.

Affected Version(s)

DRYiCE MyXalytics 6.3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.