CVE-2017-1331
- EPSS 0.27%
- Published 04.08.2017 16:29:00
- Last modified 20.04.2025 01:37:25
IBM Content Navigator 2.0.3 and 3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi...
CVE-2017-1282
- EPSS 0.23%
- Published 22.05.2017 20:29:00
- Last modified 20.04.2025 01:37:25
IBM Content Navigator & CMIS 2.0 and 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi...
CVE-2017-1146
- EPSS 0.23%
- Published 20.03.2017 16:59:01
- Last modified 20.04.2025 01:37:25
IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with...
CVE-2015-1888
- EPSS 0.17%
- Published 03.10.2015 22:59:08
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.2 before 2.0.2-ICN-FP007 and 2.0.3 before 2.0.3-ICN-FP003, as used in Content Manager, FileNet Content Manager, Content Foundation, Content Manager OnDemand, and other products, al...
CVE-2014-8911
- EPSS 0.24%
- Published 14.02.2015 02:59:32
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 before 2.0.3.2 FP002 allows remote attackers to inject arbitrary web script or HTML via the Accept-Language HTTP header.
CVE-2014-0874
- EPSS 0.19%
- Published 28.02.2014 06:18:54
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter.
CVE-2014-0858
- EPSS 0.12%
- Published 27.02.2014 20:55:06
- Last modified 12.04.2025 10:46:40
IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to bypass intended access restrictions and conduct deleteAction attacks via a modified URL.
CVE-2013-5462
- EPSS 0.25%
- Published 19.12.2013 22:55:04
- Last modified 11.04.2025 00:51:21
IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.0.2 before 2.0.2.1-ICN-FP001 allows remote attackers to conduct clickjacking attacks via vectors involving FRAME element...