HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.
References
Link | Resource |
---|---|
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 | Vendor Advisory |
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Jun 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 |
Information
Published : 2024-01-03 03:15
Updated : 2025-06-18 16:15
NVD link : CVE-2023-50343
Mitre link : CVE-2023-50343
CVE.ORG link : CVE-2023-50343
JSON object : View
Products Affected
hcltech
- dryice_myxalytics
CWE