Broken Authentication in HCL MyXalytics Exposes Sensitive Data
CVE-2024-42172
5.3MEDIUM
Key Information:
- Vendor
- HCL Software Software
- Status
- Dryice Myxalytics
- Vendor
- CVE Published:
- 11 January 2025
Summary
HCL MyXalytics is impacted by a broken authentication vulnerability that permits attackers to seize keys, passwords, and session tokens. This flaw may result from suboptimal configurations, logic flaws, or software issues, creating conditions for unauthorized access and potential identity theft. Applications with access control, including databases, network infrastructure, and web applications, may be affected, leaving sensitive information vulnerable to exploitation.
Affected Version(s)
DRYiCE MyXalytics 6.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database