CVE-2023-45722: Path Traversal Arbitrary File Read affects DRYiCE MyXalytics
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory. The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45722?
CVE-2023-45722 is classified as a high severity vulnerability due to its potential for arbitrary file read exploitation.
What software versions are affected by CVE-2023-45722?
The affected software versions for CVE-2023-45722 include HCL DRYiCE MyXalytics versions 5.9, 6.0, and 6.1.
How do I fix CVE-2023-45722?
To fix CVE-2023-45722, users should apply the latest security patches provided by HCL for the affected versions.
What type of vulnerability is CVE-2023-45722?
CVE-2023-45722 is a path traversal vulnerability that allows for arbitrary file reading due to improper input handling.
How can CVE-2023-45722 affect my system?
CVE-2023-45722 can potentially expose sensitive files on the server, leading to data breaches or unauthorized access.