HCL Unica Centralized Offer Management是印度HCL公司的一个负责优惠的统一管理和分发的模块。 HCL Unica Centralized Offer Management存在安全漏洞,该漏洞源于异常处理不当,可能导致敏感信息泄露,进而导致远程代码执行或拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | Unica Centralized Offer Management | <=25.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-52616 | 5.3 MEDIUM | HCL Unica 12.1.10 is affected by an exposure of sensitive information |
| CVE-2025-31992 | 4.6 MEDIUM | HCL MaxAI Assistant is susceptible to a HTML injection vulnerability |
| CVE-2025-31997 | 4.2 MEDIUM | HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References |
| CVE-2025-31969 | 4.0 MEDIUM | HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP) |
| CVE-2025-52615 | 3.5 LOW | HCL Unica Platform is impacted by misconfigured security related HTTP headers |
| CVE-2025-52614 | 3.5 LOW | HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability |
| CVE-2025-31993 | 3.5 LOW | HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Fo |
No comments yet