HCL Unica Centralized Offer Management Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object References (IDOR) has been identified in HCL Unica Centralized Offer Management versions 25.1 and lower. This vulnerability allows an attacker to bypass authorization and directly access resources within the system, such as database records or files.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive resources, including database records and files.

Remediation

Users are advised to upgrade to HCL Unica Centralized Offer Management version 25.1.0.1, available from the My HCLSoftware Portal.

Added: Oct 12, 2025, 3:16 AM
Updated: Oct 12, 2025, 3:16 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.8
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.