Content Navigator

Vendor:

First CVE: Dec 19, 2013 · Active for 12 years

40
Total CVEs
More Total CVEs than 98% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Content Navigator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2013
12 years ago
Most Recent CVE
Apr 2, 2026
116 days ago

CVE Severity & Scoring

Content Navigator40 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local1 (2.5%)
Network34 (85.0%)
Unknown5 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (87.5%)
High0 (0.0%)
Unknown5 (12.5%)
User Interaction
None15 (37.5%)
Unknown5 (12.5%)
Required20 (50.0%)
Privileges Required
Low27 (67.5%)
High1 (2.5%)
None7 (17.5%)
Unknown5 (12.5%)

Top CVEs

Signals from CVEs in this product scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Content Navigator 3.0CD is could allow an attacker to execute arbitrary code on a user's workstation. When editing an executable file in ICN with Edit service, it will be execu
Mar 14, 20198.829NONO
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an aut
Dec 7, 20228.828NONO
IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559.
Mar 24, 20208.825NONO
IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expo
Jan 29, 20188.225NONO
IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadshe
Feb 7, 20187.824NONO
IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web
Apr 2, 20265.421NONO
IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the
Dec 21, 20206.421NONO
IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted
Apr 25, 20196.121NONO
IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript
Oct 4, 20235.420NONO
IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.
Aug 9, 20216.520NONO

Exploit Exposure

Signals from CVEs in this product scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (40 CVEs).

Media Mentions

Signals from CVEs in this product scope (40 CVEs).

Top CNAs Publishing CVEs For Content Navigator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.2.025.30.3%00
3.1.045.50.2%00
3.0.823.50.9%00
3.0.723.50.9%00
3.0.337.11.4%00
3.0.237.11.4%00
3.0.1545.50.2%00
3.0.1415.40.4%00
3.0.1325.40.3%00
3.0.1145.50.3%00
3.0.146.00.7%00
3.0.0275.60.9%00
2.0.3.835.40.6%00
2.0.3.725.40.6%00
2.0.3.625.40.6%00
2.0.3.525.40.6%00
2.0.375.41.0%00
2.0.2.817.80.9%00
2.0.2.717.80.9%00
2.0.243.71.2%00