CVE Vulnerabilities

CVE-2018-1366

Published: Feb 07, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

Affected Software

NameVendorStart VersionEnd Version
Content_navigatorIbm2.0.2.7 (including)2.0.2.7 (including)
Content_navigatorIbm2.0.2.8 (including)2.0.2.8 (including)
Content_navigatorIbm3.0.0 (including)3.0.0 (including)
Content_navigatorIbm3.0.1 (including)3.0.1 (including)
Content_navigatorIbm3.0.2 (including)3.0.2 (including)
Content_navigatorIbm3.0.3 (including)3.0.3 (including)

References