📦 Datacap Navigator

by Ibm

🔍 What is Datacap Navigator?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-4902

HIGH CVSS 8.8 Jul 1, 2021

This SQL injection vulnerability in IBM Datacap Taskmaster Capture allows remote attackers to execute arbitrary SQL commands against the back-end database. Attackers could potentially view, modify, or...

CVE-2025-36026

MEDIUM CVSS 4.3 Jun 28, 2025

IBM Datacap versions 9.1.7-9.1.9 fail to set the Secure attribute on authorization tokens and session cookies, allowing attackers to intercept these cookies via HTTP links. This affects all users of v...

CVE-2024-39730

MEDIUM CVSS 5.4 Jun 28, 2025

This vulnerability in IBM Datacap Navigator allows attackers to perform clickjacking attacks. By tricking users into visiting malicious websites, attackers can hijack user clicks to perform unauthoriz...

CVE-2024-39735

MEDIUM CVSS 5.4 Jul 15, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Datacap Navigator versions 9.1.5 through 9.1.9. An authenticated attacker can inject malicious JavaScript into the web interface, p...

CVE-2024-39741

MEDIUM CVSS 4.3 Jul 15, 2024

This vulnerability allows remote attackers to perform directory traversal attacks on IBM Datacap Navigator systems. By sending specially crafted URLs containing 'dot dot' sequences (/../), attackers c...

CVE-2024-39739

MEDIUM CVSS 5.4 Jul 15, 2024

This CVE describes a server-side request forgery (SSRF) vulnerability in IBM Datacap Navigator versions 9.1.5 through 9.1.9. An authenticated attacker could exploit this to make unauthorized requests ...

CVE-2024-39728

MEDIUM CVSS 6.4 Jul 15, 2024

This stored cross-site scripting (XSS) vulnerability in IBM Datacap Navigator allows authenticated users to inject malicious JavaScript into the web interface. When exploited, it can steal session cre...

CVE-2024-39736

MEDIUM CVSS 6.5 Jul 15, 2024

IBM Datacap Navigator versions 9.1.5 through 9.1.9 are vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attackers to inject malicious HTTP headers, potential...