HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR).  An attacker can bypass authorization and access resources in the system directly, for example database records or files.
                
            References
                    | Link | Resource | 
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124422 | Vendor Advisory | 
Configurations
                    History
                    29 Oct 2025, 17:27
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124422 - Vendor Advisory | |
| First Time | Hcltech Hcltech unica Centralized Offer Management | |
| CPE | cpe:2.3:a:hcltech:unica_centralized_offer_management:*:*:*:*:*:*:*:* | 
12 Oct 2025, 03:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-10-12 03:15
Updated : 2025-10-29 17:27
NVD link : CVE-2025-31997
Mitre link : CVE-2025-31997
CVE.ORG link : CVE-2025-31997
JSON object : View
Products Affected
                hcltech
- unica_centralized_offer_management
CWE
                
                    
                        
                        CWE-639
                        
            Authorization Bypass Through User-Controlled Key
