CVE Vulnerabilities

CVE-2024-42178

Authentication Bypass Using an Alternate Path or Channel

Published: Apr 17, 2025 | Modified: May 16, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Dryice_myxalytics Hcltech 6.3 (including) 6.3 (including)

Potential Mitigations

References