{"id":"CVE-2025-27906","title":"IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL","summary":"IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the …","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-548"],"vendor":"ibm","product":"content_navigator","affected":["content_navigator = 3.0.11","content_navigator = 3.0.15","content_navigator = 3.1.0","content_navigator = 3.2.0"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-27906","references":[{"url":"https://www.ibm.com/support/pages/node/7247854","label":"psirt@us.ibm.com"}],"tags":["nvd"],"epss":0.00306,"epssPercentile":0.21421,"ingestedAt":"2026-10-08T11:31:27.384Z","slug":"CVE-2025-27906","body":"## Overview\n\nIBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.\n\n## Affected\n\n- `content_navigator = 3.0.11`\n- `content_navigator = 3.0.15`\n- `content_navigator = 3.1.0`\n- `content_navigator = 3.2.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}