First published: Wed Apr 10 2024(Updated: )
HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL MyXalytics |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50347 is considered a high-severity vulnerability due to its potential to allow arbitrary SQL command execution.
To remediate CVE-2023-50347, ensure that all database inputs are properly sanitized and implement access controls to restrict SQL command execution.
CVE-2023-50347 affects the HCL DRYiCE MyXalytics software.
An attacker exploiting CVE-2023-50347 can execute malicious SQL queries, potentially altering system configurations.
As of now, check the HCL support documentation for specific updates or patches addressing CVE-2023-50347.