CVE Vulnerabilities

CVE-2023-50343

Published: Jan 03, 2024 | Modified: Jan 09, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.

Affected Software

Name Vendor Start Version End Version
Dryice_myxalytics Hcltech 5.9 (including) 5.9 (including)
Dryice_myxalytics Hcltech 6.0 (including) 6.0 (including)
Dryice_myxalytics Hcltech 6.1 (including) 6.1 (including)

References