CVE-2026-11707 – IBM Tivoli System Automation Application Manager
“Even an administrative login page becomes a security risk when untrusted content is allowed to execute.”
This patch addresses CVE-2026-11707, a Cross-Site Scripting (XSS) vulnerability (CWE-79) affecting IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server. The CVSS score is 9.3, which is Critical severity. No verified real-world exploitation has been reported.
The vulnerability exists in the administrative console login page, where improper handling of user-supplied input could allow malicious scripts to execute in a user’s browser. Successful exploitation could compromise the confidentiality and integrity of an administrator’s session, potentially leading to unauthorized actions within the administrative console. The vulnerability is not identified as Remote Code Execution (RCE) or Elevation of Privilege (EoP). IBM has released a security update to correct the input validation issue, and organizations should prioritize deployment due to the Critical severity.
Key Details
- Affected Product
- Ibm Websphere Application Server
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-79