Cross-Site Scripting Vulnerability in IBM TRIRIGA Application Platform
CVE-2026-11372

5.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
22 June 2026

What is CVE-2026-11372?

The IBM TRIRIGA Application Platform versions 5.0.2 and 5.0.3 are susceptible to a cross-site scripting vulnerability. This issue allows authenticated users to inject arbitrary JavaScript into the web interface, potentially compromising the integrity of user sessions by exposing sensitive information including credentials. An attacker could leverage this vulnerability to manipulate page behavior or execute malicious scripts in the context of the user's session.

Affected Version(s)

TRIRIGA Application Platform 5.0.2 <= 5.0.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.