HCL Technologies DRYiCE MyXalytics是美国HCL Technologies公司的一款统一的报告和仪表板产品。 HCL Technologies DRYiCE MyXalytics 存在安全漏洞,该漏洞源于无法正确中和路径名中的特殊元素,这些元素可能导致路径名解析为受限目录之外的位置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | DRYiCE MyXalytics | 5.9, 6.0, 6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-50343 | 8.3 HIGH | Improper Access Control (Controller APIs) affects DRYiCE MyXalytics |
| CVE-2023-45724 | 8.2 HIGH | Unauthenticated File Upload affects DRYiCE MyXalytics |
| CVE-2023-50350 | 8.2 HIGH | A broken cryptographic algorithm impacts MyXalytics |
| CVE-2023-50351 | 8.2 HIGH | Insecure key rotation affects MyXalytics |
| CVE-2023-45723 | 7.6 HIGH | Path Traversal which allows file upload capability affects DRYiCE MyXalytics |
| CVE-2023-50341 | 7.6 HIGH | Improper Access Control affects DRYiCE MyXalytics |
| CVE-2023-50342 | 7.1 HIGH | Insecure Direct Object Reference (IDOR) affects DRYiCE MyXalytics |
| CVE-2023-50344 | 5.4 MEDIUM | Unauthenticated File Downloads affect DRYiCE MyXalytics |
| CVE-2023-50345 | 3.7 LOW | Open Redirect affects DRYiCE MyXalytics |
| CVE-2023-50346 | 3.1 LOW | An information disclosure affects DRYiCE MyXalytics |
| CVE-2023-50348 | 3.1 LOW | Improper Error Handling affects DRYiCE MyXalytics |
No comments yet