CVE-2024-42172

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:dryice_myxalytics:6.3:*:*:*:*:*:*:*

History

16 May 2025, 13:47

Type Values Removed Values Added
CPE cpe:2.3:a:hcltech:dryice_myxalytics:6.3:*:*:*:*:*:*:*
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118149 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118149 - Vendor Advisory
First Time Hcltech
Hcltech dryice Myxalytics
Summary
  • (es) HCL MyXalytics se ve afectado por una autenticación fallida. Esto permite a los atacantes comprometer claves, contraseñas y tokens de sesión, lo que puede provocar robo de identidad y control del sistema. Esta vulnerabilidad surge de una configuración deficiente, errores lógicos o errores de software y puede afectar a cualquier aplicación con control de acceso, incluidas bases de datos, infraestructura de red y aplicaciones web.
CWE CWE-522

11 Jan 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-11 07:15

Updated : 2025-05-16 13:47


NVD link : CVE-2024-42172

Mitre link : CVE-2024-42172

CVE.ORG link : CVE-2024-42172


JSON object : View

Products Affected

hcltech

  • dryice_myxalytics
CWE
CWE-287

Improper Authentication

CWE-522

Insufficiently Protected Credentials