Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6
allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure.
Advisories

No advisories yet.

Fixes

Solution

As a part of HCL MyXalytics v6.7, these issues have been remediated. For customers using older versions, the mitigation path will include upgrade to version 6.7 which in turn will fix the vulnerabilities during upgrade process. For fix implementation, our HCL MyXalytics support team will provide required the assistance.


Workaround

No workaround given by the vendor.

History

Fri, 10 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 09:15:00 +0000

Type Values Removed Values Added
Description Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure.
Title HCL MyXalytics is affected by a Cross-Domain Script Include vulnerability.
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2025-10-10T13:46:15.359Z

Reserved: 2025-06-18T14:03:06.891Z

Link: CVE-2025-52655

cve-icon Vulnrichment

Updated: 2025-10-10T13:46:12.470Z

cve-icon NVD

Status : Received

Published: 2025-10-10T09:15:37.593

Modified: 2025-10-10T09:15:37.593

Link: CVE-2025-52655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.