CVE-2023-45722: Path Traversal Arbitrary File Read affects DRYiCE MyXalytics

Published Jan 3, 2024
·
Updated

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.

Affected Software

3 affected components
hcltech Dryice Myxalytics=5.9
hcltech Dryice Myxalytics=6.0
hcltech Dryice Myxalytics=6.1

Event History

Jan 3, 2024
CVE Published
02:59 AM
Data Sourced
02:59 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-45722?

CVE-2023-45722 is classified as a high severity vulnerability due to its potential for arbitrary file read exploitation.

2

What software versions are affected by CVE-2023-45722?

The affected software versions for CVE-2023-45722 include HCL DRYiCE MyXalytics versions 5.9, 6.0, and 6.1.

3

How do I fix CVE-2023-45722?

To fix CVE-2023-45722, users should apply the latest security patches provided by HCL for the affected versions.

4

What type of vulnerability is CVE-2023-45722?

CVE-2023-45722 is a path traversal vulnerability that allows for arbitrary file reading due to improper input handling.

5

How can CVE-2023-45722 affect my system?

CVE-2023-45722 can potentially expose sensitive files on the server, leading to data breaches or unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203