CVE-2024-42170: Hcltech Dryice Myxalytics

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.

Affected products

  • Hcltech Dryice Myxalytics: version 6.3 only

Published 2025-01-11. Last modified 2026-06-17.