


Perceptive Security
SOC/SIEM Consultancy

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrat…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 17:11:53
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
CVE-2026-11707 affects IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server. The vulnerability is a cross-site scripting (XSS) flaw located in the administrative console login page. An attacker could potentially exploit this vulnerability to inject malicious scripts into the login page, targeting administrators or users accessing the console. The issue is currently awaiting full analysis on NVD. IBM has published a support advisory with remediation guidance. The criticality has been rated High. No additional technical details such as CVSS score or exploit status are currently available from the NVD entry.
Technical details
Mitigation steps:
Affected products:
IBM Tivoli System Automation Application Manager 4.1
IBM WebSphere Application Server
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
