CVE-2023-45724

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltech:dryice_myxalytics:5.9:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:dryice_myxalytics:6.0:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:dryice_myxalytics:6.1:*:*:*:*:*:*:*

History

09 Jan 2024, 18:34

Type Values Removed Values Added
First Time Hcltech
Hcltech dryice Myxalytics
CWE CWE-434
CPE cpe:2.3:a:hcltech:dryice_myxalytics:6.1:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:dryice_myxalytics:6.0:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:dryice_myxalytics:5.9:*:*:*:*:*:*:*
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 - Vendor Advisory
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : 9.8

03 Jan 2024, 13:48

Type Values Removed Values Added
Summary
  • (es) El producto HCL DRYiCE MyXalytics se ve afectado por una vulnerabilidad de carga de archivos no autenticados. La aplicación web permite cargar un determinado archivo sin requerir autenticación del usuario.

03 Jan 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-03 03:15

Updated : 2024-01-09 18:34


NVD link : CVE-2023-45724

Mitre link : CVE-2023-45724

CVE.ORG link : CVE-2023-45724


JSON object : View

Products Affected

hcltech

  • dryice_myxalytics
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type