2024-01-03 03:00:28 +00:00
{
"id" : "CVE-2023-50345" ,
"sourceIdentifier" : "psirt@hcl.com" ,
"published" : "2024-01-03T02:15:43.757" ,
2024-01-09 21:00:29 +00:00
"lastModified" : "2024-01-09T19:50:11.817" ,
"vulnStatus" : "Analyzed" ,
2024-01-03 03:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.\n"
2024-01-03 15:00:29 +00:00
} ,
{
"lang" : "es" ,
"value" : "HCL DRYiCE MyXalytics se ve afectado por una vulnerabilidad de Open Redirect que podr\u00eda permitir a un atacante redirigir a los usuarios a sitios maliciosos, lo que podr\u00eda provocar ataques de phishing u otras amenazas a la seguridad."
2024-01-03 03:00:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-01-09 21:00:29 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 6.1 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 2.7
} ,
2024-01-03 03:00:28 +00:00
{
"source" : "psirt@hcl.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 3.7 ,
"baseSeverity" : "LOW"
} ,
"exploitabilityScore" : 2.2 ,
"impactScore" : 1.4
}
]
} ,
2024-01-09 21:00:29 +00:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-601"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:hcltech:dryice_myxalytics:5.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D13FF107-A7BD-4925-B5A2-B44983C3713B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:hcltech:dryice_myxalytics:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F872BB54-B3D7-4C48-A8AB-893B566380E6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:hcltech:dryice_myxalytics:6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CF8533C9-FB63-45EE-8FD4-5C69CB19F362"
}
]
}
]
}
] ,
2024-01-03 03:00:28 +00:00
"references" : [
{
"url" : "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608" ,
2024-01-09 21:00:29 +00:00
"source" : "psirt@hcl.com" ,
"tags" : [
"Vendor Advisory"
]
2024-01-03 03:00:28 +00:00
}
]
}