CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-31998: unica centralized offer management before 25.1.0.1 (exclusive); +1 more affected products

CVE-2025-31998. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.00391 (percentile 0.31022), scored 2026-10-06.

Affected technology

unica centralized offer management · before 25.1.0.1 (exclusive)
hcltech

Unica Centralized Offer Management · <=25.1
HCL Software

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · User interaction required

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service. Vendor/CNA’s CVSS 3.1 assessment (base score 3.5/10) rates confidentiality impact as low; integrity and availability impact as none. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-209, CWE-703
CCR priority
39.3 /100 (P4)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.00391 · percentile 0.31129 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-31998.html