Lucene search

K
cvelistHCLCVELIST:CVE-2023-45722
HistoryJan 03, 2024 - 2:59 a.m.

CVE-2023-45722 Path Traversal Arbitrary File Read affects DRYiCE MyXalytics

2024-01-0302:59:05
HCL
www.cve.org
6
hcl dryice myxalytics
path traversal
arbitrary file read
security vulnerability
potential exploits

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.001

Percentile

39.4%

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory. Β The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "DRYiCE MyXalytics",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "5.9, 6.0, 6.1"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.001

Percentile

39.4%

Related for CVELIST:CVE-2023-45722