External risk intelligence

HCL Unica Centralized Offer Management SSRF Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-31993

HCL Unica Centralized Offer Management is an enterprise marketing application typically deployed as a web-based service. Such applications are commonly exposed to the internet or wide internal networks to allow users and external systems to access marketing campaign data and offer management interfaces, making the vulnerable input surface reachable in typical deployment scenarios.

Server-Side Request Forgery

Hcltech Unica Centralized Offer Management

before 25.1.0.1

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in HCL Unica Centralized Offer Management, a system used for managing marketing offers. The vulnerability, known as Server-Side Request Forgery (SSRF), allows an attacker to trick the application into making unintended requests to internal or external resources, potentially exposing sensitive information or disrupting services. The main concern is confirming if this technology is in use and if it is exposed to potential threats.

  • A flaw lets attackers make the system request unintended data.
  • It impacts enterprise marketing systems, requiring attention.
  • Confirm if this system is used and if it is exposed.

Attack Path

How an attacker could exploit the issue

An attacker can exploit a server-side request forgery vulnerability in HCL Unica Centralized Offer Management by sending specially crafted input to the application. This improper input validation allows an unauthenticated attacker to trick the server into making requests to arbitrary internal or external resources, potentially leading to compromised data and system control.

  • No authentication or privileges required.
  • Submitting malicious input triggers the vulnerability.
  • Allows unauthorized server-side requests.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to trick the application into making unintended requests to internal or external resources, potentially exposing sensitive system information or enabling unauthorized access.

  • System data could be exposed.
  • Malicious input could trigger requests.
  • Unauthorized access to internal systems.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership for HCL Unica Centralized Offer Management vulnerabilities typically falls to the platform or application teams responsible for its operation, in coordination with network and security teams for exposure assessment and remediation planning. The first practical step is to confirm the presence and reachability of the affected technology, identify the accountable business owner, and then prioritize action based on potential business impact and risk.

  • Platform or application owners should lead.
  • Verify exposure and business criticality first.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is HCL Unica Centralized Offer Management?

It is an enterprise marketing software used by organizations to design, manage, and deliver targeted customer offers across various communication channels. It functions as a web-based service that integrates campaign data to automate marketing workflows, often interacting with other internal business systems and external databases to synchronize offer availability and performance metrics.

What does CVE-2025-31993 mean for this software?

This vulnerability is classified as CWE-918, or Server-Side Request Forgery (SSRF). In simple terms, it means the application fails to properly check user input, allowing an attacker to manipulate the server into making unauthorized network requests. Instead of performing its intended task, the server is tricked into fetching data from internal systems or external sites on the attacker's behalf.

How is this SSRF vulnerability triggered?

An attacker triggers the flaw by sending specially crafted input to the application. Because the software does not properly validate this data, it interprets the malicious input as a legitimate command to connect to a specific resource. It is important to note that this does not require any authentication or user privileges; the application processes the request simply because it was sent to an exposed input point.

Is my deployment of this software at risk?

According to Halo Surface Signal, this software is typically deployed as a web-based service and is often reachable via the internet or wide internal networks. If your instance is configured to be accessible to external traffic, it faces a higher likelihood of being reachable by unauthorized parties compared to systems restricted to highly segmented, private networks.

What should I do if I run this technology?

Your first step is to confirm if your organization uses HCL Unica Centralized Offer Management and locate the specific version. Verify if your instance is reachable from untrusted networks, then identify the business owners responsible for the application. Coordinate with your platform and security teams to prioritize updates and ensure your configuration aligns with the latest vendor guidance for secure operation.

References