CVE-2025-27906

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.
References
Link Resource
https://www.ibm.com/support/pages/node/7247854 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:content_navigator:3.0.11:-:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.0.15:-:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.1.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.2.0:-:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Oct 2025, 14:31

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7247854 - () https://www.ibm.com/support/pages/node/7247854 - Vendor Advisory
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.2.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.1.0:-:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.0.11:-:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.0.15:-:*:*:*:*:*:*
First Time Linux
Microsoft windows
Linux linux Kernel
Microsoft
Apple
Ibm
Ibm content Navigator
Apple macos

14 Oct 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 15:16

Updated : 2025-10-21 14:31


NVD link : CVE-2025-27906

Mitre link : CVE-2025-27906

CVE.ORG link : CVE-2025-27906


JSON object : View

Products Affected

apple

  • macos

linux

  • linux_kernel

ibm

  • content_navigator

microsoft

  • windows
CWE
CWE-548

Exposure of Information Through Directory Listing