Junglewise Threat Intelligence

CVE-2026-11383: IBM WebSphere Application Server XSS in Administrative Console

CVE-2026-11383 · Severity: medium · CVSS 5.4 · Published 2026-07-30

Executive brief

IBM Tivoli System Automation Application Manager and WebSphere Application Server are affected by a security vulnerability in their administrative management interface. This flaw allows an attacker to inject malicious scripts into the console, which could then be executed in the browser of a legitimate administrator. If exploited, this could lead to unauthorized actions being performed on behalf of the administrator or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Administrative Console of IBM WebSphere Application Server, which is utilized by IBM Tivoli System Automation Application Manager. The vulnerability is caused by improper neutralization of user-supplied input during web page generation (CWE-79). A remote authenticated attacker with low privileges can exploit this by injecting malicious JavaScript into the console. Execution occurs when a victim user (typically an administrator) interacts with the affected page, potentially allowing the attacker to disclose credentials, hijack sessions, or perform unauthorized administrative tasks. The vulnerability affects WebSphere Application Server versions 8.5 and 9.0 as integrated with Tivoli System Automation Application Manager 4.1.

Affected products

  • IBM Tivoli System Automation Application Manager 4.1
  • IBM WebSphere Application Server 8.5, 9.0

Timeline

  • 2026-07-24: advisory: Initial publication by IBM
  • 2026-07-30: disclosed: NVD publication date

References

Related threats