CVE-2025-31998CRITICAL 3.5EPSS p30.9%
CVE-2025-31998CVE-2025-31998
hcltech / unica_centralized_offer_management
Description
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service.
Scoring
| CVSS 3.1 | 3.5 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N |
| EPSS | 0.39% probability of exploitation · percentile 30.9% · 2026-10-05T12:00:23Z |
| Published | 2025-10-12 |
| Last modified | 2026-09-30 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Generation of Error Message Containing Sensitive Informationcwe-209 | 0% | live |
| Weakness | Improper Check or Handling of Exceptional Conditionscwe-703 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.