CVE-2026-11707: Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Tivoli System Automation Application Managerto a version that resolves this vulnerability.Fixed in 4.1 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 8.5 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 9.0 - Compensating control
Review and apply the remediations from IBM Security Bulletin referenced as 'Security Bulletin: IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities (CVE-2026-11594, CVE-2026-11707, CVE-2026-11383)' for the affected WebSphere versions shipped with Tivoli System Automation Application Manager (IBM WebSphere Application Server 8.5 and 9.0).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11707?
CVE-2026-11707 has a risk level of 32, indicating a moderate severity in the context of web application security.
What type of vulnerability is CVE-2026-11707?
CVE-2026-11707 is a cross-site scripting vulnerability affecting the administrative console login page of IBM WebSphere Application Server.
How do I fix CVE-2026-11707?
To fix CVE-2026-11707, ensure that your IBM WebSphere Application Server is updated to the latest version provided by IBM.
Who is affected by CVE-2026-11707?
Any users or administrators relying on IBM WebSphere Application Server's administrative console login page may be affected by CVE-2026-11707.
When was CVE-2026-11707 published?
CVE-2026-11707 was published on June 23, 2026.