
CVE-2019-4035
https://notcve.org/view.php?id=CVE-2019-4035
22 Mar 2019 — IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit client will download documents from the fake ICN website. IBM X-Force ID: 156001. IBM Content Navigator 3.0CD podría permitir que los atacantes dirijan el tráfico web a un sitio malicioso. • http://www.ibm.com/support/docview.wss?uid=ibm10869060 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2019-4034
https://notcve.org/view.php?id=CVE-2019-4034
14 Mar 2019 — IBM Content Navigator 3.0CD is could allow an attacker to execute arbitrary code on a user's workstation. When editing an executable file in ICN with Edit service, it will be executed on the user's workstation. IBM X-Force ID: 156000. IBM Content Navigator 3.0CD podría permitir que un atacante ejecute código arbitrario en el puesto de trabajo de un usuario. Al editar un archivo ejecutable en ICN con el servicio "Edit", se ejecutará en el puesto de trabajo del usuario. • http://www.securityfocus.com/bid/107426 •

CVE-2018-1496
https://notcve.org/view.php?id=CVE-2018-1496
31 May 2018 — IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141219. IBM Content Navigator, en sus versiones 2.0.3, 3.0.0, 3.0.1, 3.0.2 y 3.0.3 , es vulnerable a ataques de tipo Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban códig... • http://www.ibm.com/support/docview.wss?uid=swg22015420 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1366
https://notcve.org/view.php?id=CVE-2018-1366
07 Feb 2018 — IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452. IBM Content Navigator 2.0 y 3.0 es vulnerable a una inyección CSV (Comma Separated Value). Un atacante podría explotar esta vulnerabilidad para explotar otras vulnerabilidades en software de hojas de cálculo. • http://www.ibm.com/support/docview.wss?uid=swg22012674 •

CVE-2018-1364
https://notcve.org/view.php?id=CVE-2018-1364
29 Jan 2018 — IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 137449. Las versiones 2.0 y 3.0 de IBM Content Navigator son vulnerables a ataques de tipo XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información sensible o consumir recursos de ... • http://www.ibm.com/support/docview.wss?uid=swg22012595 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2017-1522
https://notcve.org/view.php?id=CVE-2017-1522
05 Oct 2017 — IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129832. IBM Content Navigator CMIS, en sus versiones 2.0.3, 3.0.0 y 3.0.1, es vulnerable a ataques Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario e... • http://www.ibm.com/support/docview.wss?uid=swg22008162 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1502
https://notcve.org/view.php?id=CVE-2017-1502
07 Sep 2017 — IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129577. IBM Content Navigator CMIS 2.0.3, 3.0.0 y 3.0.1 es vulnerable a ataques de tipo Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interf... • http://www.ibm.com/support/docview.wss?uid=swg22006941 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1331
https://notcve.org/view.php?id=CVE-2017-1331
04 Aug 2017 — IBM Content Navigator 2.0.3 and 3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126233. Las versiones 2.0.3 y 3.0.0 de IBM Content Navigator son vulnerables a ataques de tipo cross-site scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la interfaz de usuario d... • http://www.ibm.com/support/docview.wss?uid=swg22003928 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1282
https://notcve.org/view.php?id=CVE-2017-1282
22 May 2017 — IBM Content Navigator & CMIS 2.0 and 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124760. Content Navigator & CMIS versiones 2.0 y 3.0 de IBM, es vulnerable a un problema de tipo cross-site-scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la interfaz de usua... • http://www.ibm.com/support/docview.wss?uid=swg22002356 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1146
https://notcve.org/view.php?id=CVE-2017-1146
20 Mar 2017 — IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999736. IBM Content Navigator 2.0.3 y 3.0.0 son vulnerables a secuencias de comandos en sitios cruzados. Esta vulnerabilidad permita a usuarios incrustar código JavaScript arbitrario en la Web UI alterando así la funcional... • http://www.ibm.com/support/docview.wss?uid=swg21999736 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •