Impact
The vulnerability in HCL MyXalytics allows an attacker to submit input of arbitrary length, which can overwhelm system resources and cause performance degradation or an application crash. Because the application does not impose restrictions on payload size, an unauthenticated user can trigger a denial of service. This weakness is a classic example of resource exhaustion (CWE‑770).
Affected Systems
HCL Software's MyXalytics product is impacted. All released versions are affected; no specific version numbers are listed in the advisory.
Risk and Exploitability
The CVSS score of 3.5 indicates a low severity, and the EPSS score is unavailable, implying limited evidence of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploit. Still, an attacker could exploit the flaw by sending a large payload via the application's user interface or API, leading to a denial of service. This would impact system availability rather than confidentiality or integrity. The exploit requires only that the attacker can reach the vulnerable input endpoint, making remote exploitation plausible.
OpenCVE Enrichment