Vulnerabilities > Hcltech > Dryice Myxalytics > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-01-03 CVE-2023-45724 Unrestricted Upload of File with Dangerous Type vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability.
network
low complexity
hcltech CWE-434
critical
9.8
2024-01-03 CVE-2023-45723 Path Traversal vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.
network
low complexity
hcltech CWE-22
critical
9.8
2024-01-03 CVE-2023-45722 Path Traversal vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.
network
low complexity
hcltech CWE-22
critical
9.8
2024-01-03 CVE-2023-50351 Unspecified vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data.
network
low complexity
hcltech
critical
9.1