CVE-2025-27906
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/10/2025
Last modified:
21/10/2025
Description
IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:content_navigator:3.0.11:-:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:content_navigator:3.0.15:-:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:content_navigator:3.1.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:content_navigator:3.2.0:-:*:*:*:*:*:* | ||
| cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



