← back
CVE-2023-50343highCWE-284

Improper Access Control (Controller APIs) affects DRYiCE MyXalytics

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.3epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L