
CVE-2022-43581 – IBM Content Navigator code execution
https://notcve.org/view.php?id=CVE-2022-43581
07 Dec 2022 — IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805. IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11 y 3.0.12 es vulnerable a la falta de autorización y podría permitir que un usuario autenticado cargue complementos externos y ejecute código. ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/238805 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-862: Missing Authorization •

CVE-2020-4687
https://notcve.org/view.php?id=CVE-2020-4687
20 Aug 2020 — IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they should not have access to. IBM X-Force ID: 186679. IBM Content Navigator versiones 3.0.7 y 3.0.8, podrían permitir a un usuario autenticado visualizar el contenido en memoria caché de otro usuario al que no debería tener acceso. IBM X-Force ID: 186679. • https://exchange.xforce.ibmcloud.com/vulnerabilities/186679 •

CVE-2020-4548
https://notcve.org/view.php?id=CVE-2020-4548
20 Aug 2020 — IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Content Navigator database. IBM X-Force ID: 183316. IBM Content Navigator versiones 3.0.7 y 3.0.8, es vulnerable a una comprobación de entrada inapropiada. Un administrador malicioso podría omitir la interfaz de usuario y enviar peticiones al servidor de IBM Con... • https://exchange.xforce.ibmcloud.com/vulnerabilities/183316 • CWE-20: Improper Input Validation •

CVE-2018-1496
https://notcve.org/view.php?id=CVE-2018-1496
31 May 2018 — IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141219. IBM Content Navigator, en sus versiones 2.0.3, 3.0.0, 3.0.1, 3.0.2 y 3.0.3 , es vulnerable a ataques de tipo Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban códig... • http://www.ibm.com/support/docview.wss?uid=swg22015420 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1366
https://notcve.org/view.php?id=CVE-2018-1366
07 Feb 2018 — IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452. IBM Content Navigator 2.0 y 3.0 es vulnerable a una inyección CSV (Comma Separated Value). Un atacante podría explotar esta vulnerabilidad para explotar otras vulnerabilidades en software de hojas de cálculo. • http://www.ibm.com/support/docview.wss?uid=swg22012674 •

CVE-2018-1364
https://notcve.org/view.php?id=CVE-2018-1364
29 Jan 2018 — IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 137449. Las versiones 2.0 y 3.0 de IBM Content Navigator son vulnerables a ataques de tipo XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información sensible o consumir recursos de ... • http://www.ibm.com/support/docview.wss?uid=swg22012595 • CWE-611: Improper Restriction of XML External Entity Reference •