Medium severity4.2NVD Advisory· Published Oct 12, 2025· Updated Jun 17, 2026
CVE-2025-31997
CVE-2025-31997
Description
HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
Affected products
3- cpe:2.3:a:hcltech:unica_centralized_offer_management:*:*:*:*:*:*:*:*Range: <25.1.0.1
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=25.1
Patches
Vulnerability mechanics
References
1- support.hcl-software.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.