CVE-2025-31969

HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*

History

20 Oct 2025, 16:59

Type Values Removed Values Added
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124417 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124417 - Vendor Advisory
CPE cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*
First Time Hcltech unica
Hcltech

12 Oct 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-12 08:15

Updated : 2025-10-20 16:59


NVD link : CVE-2025-31969

Mitre link : CVE-2025-31969

CVE.ORG link : CVE-2025-31969


JSON object : View

Products Affected

hcltech

  • unica
CWE
CWE-358

Improperly Implemented Security Check for Standard