9.3
CVE-2026-11707
- EPSS 0.22%
- Veröffentlicht 30.07.2026 14:15:25
- Zuletzt bearbeitet 18.08.2026 13:27:06
- CVE-Watchlists
- Unerledigt
Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Application Server Version >= 8.5 < 8.5.5.30
Ibm ≫ Websphere Application Server Version >= 9.0 < 9.0.5.29
Ibm ≫ Tivoli System Automation Application Manager Version >= 4.1.0 <= 4.1.0.7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.123 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 9.3 | 2.8 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://www.ibm.com/support/pages/node/7281073