Executive brief
HCL MyXalytics is an analytics and reporting platform used to monitor system performance and generate business insights. A vulnerability allows attackers to submit large amounts of data without restrictions, potentially causing the system to slow down or become unavailable, disrupting access for legitimate users.
Technical details
The vulnerability exists in HCL MyXalytics' input handling mechanism, which lacks validation on the number of characters users can submit. This insufficient input validation enables a denial-of-service (DoS) attack where an attacker can send excessively large payloads to consume system resources such as memory, CPU, or disk space. The attack vector is network-based and requires no authentication or special privileges. By submitting large amounts of data repeatedly, an attacker can degrade system performance or cause the application to become unresponsive. The vulnerability has been assigned CVE-2025-52657 with a CVSS score of 3.5.
Affected products
- HCL MyXalytics
Timeline
- 2026-09-07: disclosed