CVE 4.2 MEDIUM

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR)_CVE-2025-31997

4.2 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N

Description

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.

Basic Information

ID CVE-2025-31997
Source HCL
Published Oct 12, 2025 at 02:27

Affected Product

Vendor HCL Software
Product Unica Centralized Offer Management
Version <=25.1
Affected Versions HCL Software Unica Centralized Offer Management <=25.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.