cve/2023/CVE-2023-50343.md

18 lines
728 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-50343](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50343)
![](https://img.shields.io/static/v1?label=Product&message=DRYiCE%20MyXalytics&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%205.9%2C%206.0%2C%206.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds