CVE-2025-27906

MEDIUM

IBM Content Navigator <3.2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7247854

Scores

CVSS v3 5.3
EPSS 0.0003
EPSS Percentile 9.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-548
Status published
Products (4)
ibm/content_navigator 3.0.11
ibm/content_navigator 3.0.15
ibm/content_navigator 3.1.0
ibm/content_navigator 3.2.0
Published Oct 14, 2025
Tracked Since Feb 18, 2026