HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech unica Centralized Offer Management
|
|
| CPEs | cpe:2.3:a:hcltech:unica_centralized_offer_management:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hcltech unica Centralized Offer Management
|
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech unica |
|
| Vendors & Products |
Hcltech
Hcltech unica |
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 12 Oct 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files. | |
| Title | HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2025-10-12T02:27:25.913Z
Updated: 2025-10-14T14:53:48.041Z
Reserved: 2025-04-01T18:46:35.961Z
Link: CVE-2025-31997
Updated: 2025-10-14T14:31:41.750Z
Status : Analyzed
Published: 2025-10-12T03:15:34.393
Modified: 2025-10-29T17:27:23.037
Link: CVE-2025-31997
No data.