CVE-2023-50347: Insecure SQL Interface affects HCL DRYiCE MyXalytics
HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50347?
CVE-2023-50347 is considered a high-severity vulnerability due to its potential to allow arbitrary SQL command execution.
How do I fix CVE-2023-50347?
To remediate CVE-2023-50347, ensure that all database inputs are properly sanitized and implement access controls to restrict SQL command execution.
What systems are affected by CVE-2023-50347?
CVE-2023-50347 affects the HCL DRYiCE MyXalytics software.
What kind of attacks can exploit CVE-2023-50347?
An attacker exploiting CVE-2023-50347 can execute malicious SQL queries, potentially altering system configurations.
Is there a patch available for CVE-2023-50347?
As of now, check the HCL support documentation for specific updates or patches addressing CVE-2023-50347.