{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-27906","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-03-10T17:14:11.135Z","datePublished":"2025-10-14T14:08:42.994Z","dateUpdated":"2025-10-14T19:09:55.400Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:content_navigator:3.0.11:*:*:*:*:*:*:*","cpe:2.3:a:ibm:content_navigator:3.0.15:*:*:*:*:*:*:*","cpe:2.3:a:ibm:content_navigator:3.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:content_navigator:3.2.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"Content Navigator","vendor":"IBM","versions":[{"status":"affected","version":"3.0.11"},{"status":"affected","version":"3.0.15"},{"status":"affected","version":"3.1.0"},{"status":"affected","version":"3.2.0"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified."}],"value":"IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-548","description":"CWE-548 Exposure of Information Through Directory Listing","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2025-10-14T14:08:42.994Z"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7247854"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<h2>Remediation/Fixes</h2><p></p><div><table><tbody><tr><td>Affected Product(s)</td><td>Version(s)</td><td>Fix</td></tr><tr><td>IBM Content Navigator</td><td>3.0.11</td><td>ICN 3.0.11-IF021</td></tr><tr><td>IBM Content Navigator</td><td>3.0.15</td><td>ICN 3.0.15-IF007</td></tr><tr><td>IBM Content Navigator</td><td>3.1.0</td><td>ICN 3.1.0-IF6</td></tr><tr><td>IBM Content Navigator</td><td>3.2.0</td><td>ICN 3.2.0-IF1</td></tr></tbody></table></div>\n\n<br>"}],"value":"Remediation/Fixes\n\nAffected Product(s)Version(s)FixIBM Content Navigator3.0.11ICN 3.0.11-IF021IBM Content Navigator3.0.15ICN 3.0.15-IF007IBM Content Navigator3.1.0ICN 3.1.0-IF6IBM Content Navigator3.2.0ICN 3.2.0-IF1"}],"source":{"discovery":"UNKNOWN"},"title":"IBM Content Navigator information disclosure","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-14T19:09:46.865547Z","id":"CVE-2025-27906","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-14T19:09:55.400Z"}}]}}