CVE-2025-27906
IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.29%
- CWE
- CWE-548
- Published
- 2025-10-14
- Last modified
- 2026-03-13
Affected products
- IBM Content Navigator
- IBM Content Navigator
- IBM Content Navigator
- IBM Content Navigator
Weakness type
Related vulnerabilities
- CVE-2026-19987 — SourceCodester Best Employee Management System Profile exposure of information through directory listing
- CVE-2026-50233 — Lyrion Music Server 9.2.0 Arbitrary Directory Listing
- CVE-2025-32750 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory...
- CVE-2026-41933 — Vvveb < 1.0.8.3 Directory Listing Information Disclosure
- CVE-2026-22860 — Rack has a Directory Traversal via Rack:Directory
- CVE-2023-38265 — Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]
- CVE-2020-36921 — RED-V Super Digital Signage System 5.1.1 Log Information Disclosure Vulnerability
- CVE-2022-50788 — SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory