IBM Content Navigator HTML Injection Vulnerability

Vulnerability

A HTML injection vulnerability has been identified in IBM Content Navigator versions 3.0.11, 3.0.15, and 3.1.0. This vulnerability allows remote attackers to inject malicious HTML code, which would be executed in the context of the victim's web browser and the hosting site.

Impact

Exploitation of this vulnerability allows for HTML injection, which can be used to execute malicious scripts in the context of the user's browser.

Remediation

Users can upgrade to IBM Content Navigator versions 3.0.15 IF006, 3.1.0 IF004, or 3.0.11 IF020. Additionally, using HTTPS to encrypt data in transit can help mitigate exposure to this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.7
exploitability
4.6
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.