CVE-2025-31997

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/10/2025
Last modified:
29/10/2025

Description

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:unica_centralized_offer_management:*:*:*:*:*:*:*:* 25.1.0.1 (excluding)