Cross-Site Scripting Vulnerability in IBM Tivoli System Automation and WebSphere Application Server
CVE-2026-11707

9.3CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 July 2026

What is CVE-2026-11707?

A cross-site scripting vulnerability exists in the administrative console login page of IBM Tivoli System Automation Application Manager and IBM WebSphere Application Server. This flaw could allow an attacker to inject malicious scripts into the application, potentially leading to unauthorized actions and compromising user session integrity. Users are advised to apply the necessary patches to mitigate the risk and secure their environments.

Affected Version(s)

Tivoli System Automation Application Manager 4.1

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.