Lucene search

K
nvd[email protected]NVD:CVE-2023-45722
HistoryJan 03, 2024 - 3:15 a.m.

CVE-2023-45722

2024-01-0303:15:09
CWE-22
web.nvd.nist.gov
hcl dryice myxalytics
path traversal
arbitrary file read
vulnerability
external input
restricted directory
potential exploits
application security

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.4%

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory. Β The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.

Affected configurations

NVD
Node
hcltechdryice_myxalyticsMatch5.9
OR
hcltechdryice_myxalyticsMatch6.0
OR
hcltechdryice_myxalyticsMatch6.1

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.4%

Related for NVD:CVE-2023-45722