---
id: CVE-2025-31997
title: >-
  HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object
  References (IDOR)
summary: >-
  HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object
  References (IDOR).  An attacker can bypass authorization and access resources
  in the system directly, for example database records or files.
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: hcltech
product: unica_centralized_offer_management
affected:
  - unica_centralized_offer_management < 25.1.0.1
patched:
  - unica_centralized_offer_management 25.1.0.1
published: '2025-10-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31997'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124422
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00224
epssPercentile: 0.11895
ingestedAt: '2026-10-08T13:42:55.115Z'
---

## Overview

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR).  An attacker can bypass authorization and access resources in the system directly, for example database records or files.

## Affected

- `unica_centralized_offer_management < 25.1.0.1`

## Remediation

Upgrade past the affected range:

- `unica_centralized_offer_management 25.1.0.1`
