CVE Vulnerabilities

CVE-2025-27906

Exposure of Information Through Directory Listing

Published: Oct 14, 2025 | Modified: Oct 21, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

Name Vendor Start Version End Version
Content_navigator Ibm 3.0.11 (including) 3.0.11 (including)
Content_navigator Ibm 3.0.15 (including) 3.0.15 (including)
Content_navigator Ibm 3.1.0 (including) 3.1.0 (including)
Content_navigator Ibm 3.2.0 (including) 3.2.0 (including)

Potential Mitigations

References