First published: Wed Nov 01 2023(Updated: )
IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | <=3.0.14 | |
IBM Content Navigator | <=3.0.13 | |
IBM Content Navigator | <=3.0.11 | |
IBM Content Navigator | =3.0.13 | |
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-35896 is medium with a score of 5.4.
IBM Content Navigator server-side request forgery (SSRF) is a vulnerability that allows an authenticated attacker to send unauthorized requests from the system, potentially facilitating other attacks.
An authenticated attacker can exploit CVE-2023-35896 by utilizing server-side request forgery (SSRF) to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
To fix CVE-2023-35896, apply the patch provided by IBM for IBM Content Navigator version 3.0.13 or upgrade to version 3.0.14.
You can find more information about CVE-2023-35896 on the IBM support page and IBM X-Force ID 259247.