CVE-2025-31993: Hcltech Unica Centralized Offer Management

Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted input to a target application running on a server.

Affected products

  • Hcltech Unica Centralized Offer Management: before 25.1.0.1 (fixed in 25.1.0.1)

Published 2025-10-12. Last modified 2026-10-08.