CVE-2024-42172

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:dryice_myxalytics:6.3:*:*:*:*:*:*:*

History

16 May 2025, 13:47

Type Values Removed Values Added
CWE CWE-522
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Hcltech
Hcltech dryice Myxalytics
CPE cpe:2.3:a:hcltech:dryice_myxalytics:6.3:*:*:*:*:*:*:*
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118149 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118149 - Vendor Advisory

11 Jan 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-11 07:15

Updated : 2025-05-16 13:47


NVD link : CVE-2024-42172

Mitre link : CVE-2024-42172


JSON object : View

Products Affected

hcltech

  • dryice_myxalytics
CWE
CWE-522

Insufficiently Protected Credentials