HCL MyXalytics Broken Authentication Vulnerability Allowing Identity Theft and System Control

Vulnerability

A broken authentication vulnerability has been identified in HCL MyXalytics. This issue allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and unauthorized control over systems. The vulnerability stems from poor configuration, logic errors, or software bugs, and can impact any application with access control, including databases, network infrastructure, and web applications.

Impact

Exploitation of this vulnerability could result in compromised authentication credentials, session tokens, and keys, leading to unauthorized access and control over user identities and systems.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.