CVE-2025-31998CRITICAL 9.8EPSS p27.4%
CVE-2025-31998CVE-2025-31998
Description
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.36% probability of exploitation · percentile 27.4% · 2026-06-19T12:03:05Z |
| Published | 2025-10-12 |
| Last modified | 2025-10-29 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Generation of Error Message Containing Sensitive Informationcwe-209 | 0% | live |
| Weakness | Improper Check or Handling of Exceptional Conditionscwe-703 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.