Directory Listing Exposure in IBM Content Navigator by IBM
CVE-2025-27906

5.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 October 2025

What is CVE-2025-27906?

IBM Content Navigator versions 3.0.11, 3.0.15, 3.1.0, and 3.2.0 have a vulnerability that may allow unauthorized users to access the directory listing of the application through specific URLs. While users can see the available application files and directories in their web browser, they cannot read or modify the file contents. It's crucial for organizations using these versions to take immediate action to mitigate this exposure and ensure that sensitive data remains secure.

Affected Version(s)

Content Navigator 3.0.11

Content Navigator 3.0.15

Content Navigator 3.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.