CVE-2015-1888
IBM Content Navigator 2.0.2-2.0.3 - Authenticated Cross-Site Scripting via Crafted URL
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.2 before 2.0.2-ICN-FP007 and 2.0.3 before 2.0.3-ICN-FP003, as used in Content Manager, FileNet Content Manager, Content Foundation, Content Manager OnDemand, and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21700205
Scores
EPSS
0.0078
EPSS Percentile
52.2%
Details
CWE
CWE-79
Status
published
Products (2)
ibm/content_navigator
2.0.2
ibm/content_navigator
2.0.3
Published
Oct 03, 2015
Tracked Since
Feb 18, 2026