Vulnerability Description
IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Content Navigator | 2.0.2.7 |
References
- http://www.ibm.com/support/docview.wss?uid=swg22012674PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/137452VDB EntryVendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22012674PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/137452VDB EntryVendor Advisory
FAQ
What is CVE-2018-1366?
CVE-2018-1366 is a vulnerability with a CVSS score of 7.8 (HIGH). IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-F...
How severe is CVE-2018-1366?
CVE-2018-1366 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1366?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Content Navigator.