Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-42172

Опубликовано: 11 янв. 2025
Источник: nvd
CVSS3: 5.3
CVSS3: 9.8
EPSS Низкий

Описание

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hcltech:dryice_myxalytics:6.3:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00208
Низкий

5.3 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-522

Связанные уязвимости

CVSS3: 5.3
github
около 1 года назад

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.

EPSS

Процентиль: 43%
0.00208
Низкий

5.3 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-522