top of page
perceptive_background_267k.jpg

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrat…

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 16:04:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

CVE-2026-11707 describes a cross-site scripting (XSS) vulnerability affecting IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server. The vulnerability exists specifically in the administrative console login page. An attacker exploiting this flaw could inject malicious scripts into the login page, potentially compromising administrator sessions or stealing credentials. IBM has published a support advisory at ibm.com to address this issue. The vulnerability has been assigned a high criticality rating. Users of the affected products are advised to review IBM's support guidance and apply any recommended patches or mitigations promptly.

Technical details

Mitigation steps:

Affected products:

IBM Tivoli System Automation Application Manager 4.1
IBM WebSphere Application Server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page