IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NIBM Aix
OSIbmall versionsIBM I
OSIbmall versionsIBM Tivoli System Automation Application Manager
APPIbm4.1.0 – 4.1.0.7IBM Websphere Application Server
APPIbm8.5 – 8.5.5.30 (excl.)9.0 – 9.0.5.29 (excl.)IBM Z\/os
OSIbmall versionsLinux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References
Related vulnerabilities
CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit