CVE-2026-11707 Details
Description
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
A cross-site scripting vulnerability has been identified in the administrative console login page of IBM Tivoli System Automation Application Manager version 4.1, which utilizes IBM WebSphere Application Server. This vulnerability allows for the injection of malicious scripts that could be executed in the context of the user's browser.
Users can refer to the IBM WebSphere Application Server Security Bulletin for guidance on addressing this vulnerability. This bulletin includes information on the necessary updates for the affected WebSphere Application Server versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7281073 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm websphere application server | >= 8.5, < 8.5.5.30 >= 9.0, < 9.0.5.29 |
CPE
Remediation
| |
| ibm aix | All versions |
CPE
Remediation
| |
| ibm i | All versions |
CPE
Remediation
| |
| ibm z/os | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| ibm tivoli system automation application manager | >= 4.1.0, <= 4.1.0.7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |