HCL Unica Centralized Offer Management Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability exists in HCL Unica Centralized Offer Management versions 25.1 and lower, due to poor unhandled exceptions that expose sensitive information. This information can be exploited by attackers to target known vulnerabilities, potentially leading to remote code execution or denial-of-service conditions.

Impact

Exploitation of this vulnerability could allow an attacker to access sensitive information, which could then be used to exploit other vulnerabilities and launch targeted attacks, such as remote code execution or causing a denial-of-service.

Remediation

Users are advised to upgrade to HCL Unica Centralized Offer Management version 25.1.0.1, available from the My HCLSoftware Portal.

Added: Oct 12, 2025, 3:19 AM
Updated: Oct 12, 2025, 3:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.