Home/Product/ibm content navigator
Product

ibm content navigator

40 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-1243
all versions
IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated u
5.4MEDIUM
CVE-2025-27906
all versions
IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an applica
5.3MEDIUM
CVE-2024-51475
all versions
IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML cod
5.4MEDIUM
CVE-2024-56341
all versions
IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated
5.4MEDIUM
CVE-2023-35896
all versions
IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send
5.4MEDIUM
CVE-2023-40684
all versions
IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulner
4.6MEDIUM
CVE-2022-43581
>= 3.0.0 and <= 3.0.12
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerab
7.5HIGH
CVE-2021-29714
all versions
IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-For
6.5MEDIUM
CVE-2021-20550
all versions
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript
5.4MEDIUM
CVE-2021-20549
all versions
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript
5.4MEDIUM
CVE-2021-20448
all versions
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript
5.4MEDIUM
CVE-2020-4934
all versions
IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a special
4.3MEDIUM
CVE-2020-4757
all versions
IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allo
6.4MEDIUM
CVE-2020-4760
all versions
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c
5.4MEDIUM
CVE-2020-4704
all versions
IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaS
5.4MEDIUM
CVE-2020-4687
all versions
IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they should no
4.3MEDIUM
CVE-2020-4548
all versions
IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user
2.7LOW
CVE-2020-4309
all versions
IBM Content Navigator 3.0CD could disclose sensitive information to an unauthenticated user which could be used to aid in further
5.3MEDIUM
CVE-2020-4253
all versions
IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate anothe
8.8HIGH
CVE-2019-4741
all versions
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to sen
5.3MEDIUM
CVE-2019-4679
all versions
IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and version t
4.3MEDIUM
CVE-2019-4571
all versions
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c
5.4MEDIUM
CVE-2019-4263
all versions
IBM Content Navigator 3.0CD is vulnerable to local file inclusion, allowing an attacker to access a configuration file in the ICN
4.3MEDIUM
CVE-2019-4092
all versions
IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By
6.1MEDIUM
CVE-2019-4033
all versions
IBM Content Navigator 2.0.3 and 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja
5.4MEDIUM
CVE-2019-4035
all versions
IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content
5.4MEDIUM
CVE-2019-4034
all versions
IBM Content Navigator 3.0CD is could allow an attacker to execute arbitrary code on a user's workstation. When editing an executab
8.8HIGH
CVE-2018-1496
all versions
IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users
5.4MEDIUM
CVE-2018-1366
all versions
IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerabi
7.8HIGH
CVE-2018-1364
all versions
IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote
8.2HIGH
CVE-2017-1522
all versions
IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to emb
5.4MEDIUM
CVE-2017-1502
all versions
IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to emb
5.4MEDIUM
CVE-2017-1331
all versions
IBM Content Navigator 2.0.3 and 3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja
5.4MEDIUM
CVE-2017-1282
all versions
IBM Content Navigator & CMIS 2.0 and 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary
5.4MEDIUM
CVE-2017-1146
all versions
IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J
5.4MEDIUM
CVE-2015-1888
all versions
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.2 before 2.0.2-ICN-FP007 and 2.0.3 before 2.0.3-ICN-FP003, a
CVE-2014-8911
all versions
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 before 2.0.
CVE-2014-0874
all versions
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users t
CVE-2014-0858
all versions
IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to bypass intended access restrictions and co
CVE-2013-5462
all versions
IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin