CVE-2025-27906

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.
References
Link Resource
https://www.ibm.com/support/pages/node/7247854 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:content_navigator:3.0.11:-:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.0.15:-:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.1.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.2.0:-:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-10-14 15:16

Updated : 2025-10-21 14:31


NVD link : CVE-2025-27906

Mitre link : CVE-2025-27906

CVE.ORG link : CVE-2025-27906


JSON object : View

Products Affected

ibm

  • content_navigator

linux

  • linux_kernel

microsoft

  • windows

apple

  • macos
CWE
CWE-548

Exposure of Information Through Directory Listing