Junglewise Threat Intelligence

CVE-2025-62319: HCL Unica blind SQL injection in backend configuration queries

CVE-2025-62319 · Severity: critical · CVSS 9.8 · Published 2026-03-16

Vendors: HCL Software, Hcltech.

Executive brief

HCL Unica and AION, platforms used for enterprise marketing automation and customer engagement, are affected by a critical security flaw. An attacker can use specially crafted inputs to trick the system's database into revealing sensitive information or modifying configuration data. This could lead to a total compromise of the marketing platform, including the theft of customer data or disruption of business operations.

Technical details

A boolean-based blind SQL injection vulnerability exists in HCL Unica and Unica Audience Central (and related AION components) due to improper neutralization of special elements in SQL commands (CWE-89). The flaw resides in application input fields used for backend configuration queries. An unauthenticated attacker can send malicious network requests containing Boolean conditions (TRUE/FALSE) to infer data from the database based on the application's response patterns. This can lead to full unauthorized access to sensitive data, integrity loss of the database, and potential service unavailability. The issue is addressed in version 25.1.1.0.1.

Affected products

  • HCL Software Unica up to (excluding) 25.1.1.0.1
  • HCL Software Unica Audience Central up to (excluding) 25.1.1.0.1
  • HCL Software AION

Timeline

  • 2026-03-16: disclosed
  • 2026-03-16: advisory

References

Related threats