IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Project Subscriptions

Vendors Products
Content Navigator Subscribe
Advisories

No advisories yet.

Fixes

Solution

Affected VersionsFixes3.0.15ICN 3.0.15 IF0093.1.0ICN 3.1.0 IF008 LA23.2.0ICN 3.2.0 IF004


Workaround

No workaround given by the vendor.

History

Thu, 02 Apr 2026 01:00:00 +0000

Type Values Removed Values Added
Description IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Content Navigator is affected by , a Cross-Site Scripting (XSS) vulnerability
First Time appeared Ibm
Ibm content Navigator
CPEs cpe:2.3:a:ibm:content_navigator:3.0.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_navigator:3.2.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm content Navigator
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-04-02T00:14:31.101Z

Reserved: 2026-01-20T18:45:11.903Z

Link: CVE-2026-1243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-02T01:16:01.317

Modified: 2026-04-02T01:16:01.317

Link: CVE-2026-1243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.