Executive brief
IBM TRIRIGA, a platform used for managing facilities and real estate operations, is affected by a security flaw that allows an authorized user to inject malicious scripts into the web interface. If exploited, an attacker could manipulate the application's behavior or steal sensitive information, such as login credentials, from other users. This could lead to unauthorized access to corporate facility data or account takeovers within the organization.
Technical details
IBM TRIRIGA Application Platform is vulnerable to a stored cross-site scripting (XSS) vulnerability (CWE-79) within its Web UI. An authenticated attacker with low privileges can inject arbitrary JavaScript code that executes in the context of other users' browser sessions. This occurs due to improper neutralization of user-supplied input during web page generation. Successful exploitation can lead to the disclosure of sensitive session information or credentials. The vulnerability is addressed in IBM TRIRIGA Application Platform 5.0.4 GA, which implements a holistic approach to XSS mitigation.
Affected products
- IBM TRIRIGA Application Platform 5.0.2 - 5.0.3
Timeline
- 2026-06-12: advisory: Initial publication by IBM
- 2026-06-22: disclosed: NVD publication date