CVE-2025-52657
Received Received - Intake

Potential Denial of Service in HCL MyXalytics

Vulnerability report for CVE-2025-52657, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: HCL Software

Description

HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system performance or availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl myxalytics *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL MyXalytics is affected by a potential denial-of-service (DOS) vulnerability. This flaw allows users to input data without any restriction on the number of characters, which could degrade system performance or make services unavailable.

Detection Guidance

This vulnerability allows excessive input data to impact system performance. To detect it, monitor for unusually large data submissions or high resource usage in HCL MyXalytics. Check application logs for input fields receiving abnormally long strings. Use network monitoring tools to identify excessive data transfers to MyXalytics endpoints.

Impact Analysis

An attacker could exploit this vulnerability by sending large amounts of data, causing the system to slow down or crash. This may lead to service disruptions, reduced productivity, or loss of access to critical functions.

Compliance Impact

This vulnerability could impact compliance by failing to ensure system availability and integrity. Regulations like GDPR and HIPAA require protecting data and ensuring service reliability, which may be compromised if systems are frequently disrupted.

Mitigation Strategies

Implement input validation to restrict the number of characters allowed in user inputs. Monitor system performance for unusual activity that may indicate a denial-of-service attempt.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-52657. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart