60 lines
2.2 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-42172",
"sourceIdentifier": "psirt@hcl.com",
"published": "2025-01-11T07:15:08.743",
"lastModified": "2025-01-11T07:15:08.743",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications."
},
{
"lang": "es",
"value": "HCL MyXalytics se ve afectado por una autenticaci\u00f3n fallida. Esto permite a los atacantes comprometer claves, contrase\u00f1as y tokens de sesi\u00f3n, lo que puede provocar robo de identidad y control del sistema. Esta vulnerabilidad surge de una configuraci\u00f3n deficiente, errores l\u00f3gicos o errores de software y puede afectar a cualquier aplicaci\u00f3n con control de acceso, incluidas bases de datos, infraestructura de red y aplicaciones web."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@hcl.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "psirt@hcl.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"references": [
{
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118149",
"source": "psirt@hcl.com"
}
]
}