First published: Fri Mar 22 2019(Updated: )
IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit client will download documents from the fake ICN website. IBM X-Force ID: 156001.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | =3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4035 is a vulnerability in IBM Content Navigator 3.0CD that allows attackers to direct web traffic to a malicious site.
CVE-2019-4035 affects IBM Content Navigator 3.0CD by allowing attackers to send links to users that direct requests to a fake ICN site, resulting in the download of documents from the fake site.
CVE-2019-4035 has a severity rating of medium (5.4).
To fix CVE-2019-4035, upgrade to a patched version of IBM Content Navigator 3.0CD or apply the recommended security updates.
You can find more information about CVE-2019-4035 on the IBM support website, SecurityFocus, and IBM X-Force Exchange.