High severity8.8NVD Advisory· Published Jan 3, 2024· Updated Jun 17, 2026
CVE-2023-45722
CVE-2023-45722
Description
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory. The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.
Affected products
5cpe:2.3:a:hcltech:dryice_myxalytics:5.9:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:hcltech:dryice_myxalytics:5.9:*:*:*:*:*:*:*
- cpe:2.3:a:hcltech:dryice_myxalytics:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:hcltech:dryice_myxalytics:6.1:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 5.9, 6.0, 6.1
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.