📦 Dryice Myxalytics

by Hcltech

🔍 What is Dryice Myxalytics?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-52656

HIGH CVSS 7.6 Oct 3, 2025

CVE-2025-52656 is a mass assignment vulnerability in HCL MyXalytics 6.6 that allows attackers to modify sensitive application fields without proper authorization. This affects organizations using HCL ...

CVE-2024-42168

HIGH CVSS 8.9 Jan 11, 2025

HCL MyXalytics has an out-of-band resource load vulnerability where attackers can host malicious web content and trick the application into fetching and processing it. This affects all users running v...

CVE-2024-42169

HIGH CVSS 7.1 Jan 11, 2025

This vulnerability in HCL MyXalytics allows attackers to access unauthorized data due to missing access control checks. It affects users of HCL MyXalytics who haven't applied the security patch. Attac...

CVE-2023-50342

HIGH CVSS 7.1 Jan 3, 2024

HCL DRYiCE MyXalytics has an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to access other users' information due to improper access controls. This affects all ...

CVE-2023-45722

HIGH CVSS 8.8 Jan 3, 2024

CVE-2023-45722 is a path traversal vulnerability in HCL DRYiCE MyXalytics that allows attackers to read arbitrary files on the system by manipulating input to access directories outside restricted pat...

CVE-2023-45724

HIGH CVSS 8.2 Jan 3, 2024

HCL DRYiCE MyXalytics has an unauthenticated file upload vulnerability that allows attackers to upload malicious files without authentication. This affects all users running vulnerable versions of the...

CVE-2023-50350

HIGH CVSS 8.2 Jan 3, 2024

HCL DRYiCE MyXalytics uses a broken cryptographic algorithm for encryption, potentially allowing attackers to decrypt sensitive information. This affects organizations using vulnerable versions of the...

CVE-2025-52654

MEDIUM CVSS 4.6 Oct 3, 2025

HCL MyXalytics v6.6 has an HTML injection vulnerability where untrusted input isn't properly sanitized before being included in web output. This allows attackers to inject arbitrary HTML content into ...

CVE-2024-42171

MEDIUM CVSS 6.4 Jan 11, 2025

HCL MyXalytics has a session fixation vulnerability where attackers can set a victim's session token via crafted URLs. This allows unauthorized access to authenticated sessions after the victim logs i...

CVE-2024-42173

MEDIUM CVSS 4.8 Jan 11, 2025

HCL MyXalytics has an improper password policy vulnerability that allows attackers to guess or brute-force passwords when usernames are known. This affects organizations using vulnerable versions of H...