---
id: CVE-2025-27906
title: >-
  IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the
  directory listing of the application upon using an application URL
summary: >-
  IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the
  directory listing of the application upon using an application URL.
  Application files and folders are visible in the browser to a user; however,
  the contents of the …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-548
vendor: ibm
product: content_navigator
affected:
  - content_navigator = 3.0.11
  - content_navigator = 3.0.15
  - content_navigator = 3.1.0
  - content_navigator = 3.2.0
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-27906'
references:
  - url: 'https://www.ibm.com/support/pages/node/7247854'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00306
epssPercentile: 0.21421
ingestedAt: '2026-10-08T11:31:27.384Z'
---

## Overview

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.

## Affected

- `content_navigator = 3.0.11`
- `content_navigator = 3.0.15`
- `content_navigator = 3.1.0`
- `content_navigator = 3.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
