---
id: CVE-2025-31998
title: >-
  HCL Unica Centralized Offer Management is vulnerable to poor unhandled
  exceptions which exposes sensitive information
summary: >-
  HCL Unica Centralized Offer Management is vulnerable to poor unhandled
  exceptions which exposes sensitive information.  An attacker can exploit use
  this information to exploit known vulnerabilities launch targeted attacks,
  such as remote…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-209
  - CWE-703
vendor: hcltech
product: unica_centralized_offer_management
affected:
  - unica_centralized_offer_management < 25.1.0.1
patched:
  - unica_centralized_offer_management 25.1.0.1
published: '2025-10-12'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31998'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124422
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00391
epssPercentile: 0.30772
ingestedAt: '2026-09-30T23:29:32.426Z'
---

## Overview

HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information.  An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service.

## Affected

- `unica_centralized_offer_management < 25.1.0.1`

## Remediation

Upgrade past the affected range:

- `unica_centralized_offer_management 25.1.0.1`
