


Perceptive Security
SOC/SIEM Consultancy

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrat…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 16:04:09
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
CVE-2026-11707 describes a cross-site scripting (XSS) vulnerability affecting IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server. The vulnerability exists specifically in the administrative console login page. An attacker exploiting this flaw could inject malicious scripts into the login page, potentially compromising administrator sessions or stealing credentials. IBM has published a support advisory at ibm.com to address this issue. The vulnerability has been assigned a high criticality rating. Users of the affected products are advised to review IBM's support guidance and apply any recommended patches or mitigations promptly.
Technical details
Mitigation steps:
Affected products:
IBM Tivoli System Automation Application Manager 4.1
IBM WebSphere Application Server
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
