HCL Unica Centralized Offer Management Sensitive Information Exposure Vulnerability
Vulnerability
A vulnerability exists in HCL Unica Centralized Offer Management versions 25.1 and lower, due to poor unhandled exceptions that expose sensitive information. This information can be exploited by attackers to target known vulnerabilities, potentially leading to remote code execution or denial-of-service conditions.
Impact
Exploitation of this vulnerability could allow an attacker to access sensitive information, which could then be used to exploit other vulnerabilities and launch targeted attacks, such as remote code execution or causing a denial-of-service.
Remediation
Users are advised to upgrade to HCL Unica Centralized Offer Management version 25.1.0.1, available from the My HCLSoftware Portal.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
