CVE-2025-31997EPSS p11.9%

CVE-2025-31997CVE-2025-31997

hcltech / unica_centralized_offer_management

Description

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.

Scoring

CVSS 4.2 ()
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
EPSS0.22% probability of exploitation · percentile 11.9% · 2026-10-10T12:00:23Z
Last modified2026-10-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.