← back
CVE-2023-45722highCWE-22

Path Traversal Arbitrary File Read affects DRYiCE MyXalytics

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
In short

DRYiCE MyXalytics has a flaw that allows attackers to read files anywhere on the server by manipulating file paths. An attacker can bypass protections and access sensitive data like passwords or configuration files.

Technical detail

Path traversal vulnerability (CWE-22) in DRYiCE MyXalytics resulting from insufficient sanitization of user-supplied pathname input. An unauthenticated or authenticated attacker can craft special characters in file path parameters to escape the intended directory restrictions and read arbitrary files on the system, potentially exposing credentials and system configuration.

Summary generated and translated by AI from the official description.
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H