No advisories yet.
Solution
An holistic approach has been implemented to address XSS vulnerabilities across the application as part of IBM TRIRIGA Application Platform 5.0.4 GA. This vulnerability is also part of it. Customers using affected versions of IBM TRIRIGA should upgrade to IBM TRIRIGA Application Platform 5.0.4 GA or a later supported release containing the fix. IBM recommends applying the latest available maintenance to ensure protection against this vulnerability. Reference : https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ETivoli&product[…]GA+Application+Platform&release=5.0.4&platform=All&function=all https://www.ibm.com/support/fixcentral/swg/selectFixes
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7276076 |
|
Mon, 22 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM TRIRIGA Cross-Site Scripting Vulnerability | |
| First Time appeared |
Ibm
Ibm tririga Application Platform |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:tririga_application_platform:5.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:tririga_application_platform:5.0.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm tririga Application Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-06-22T15:57:43.139Z
Reserved: 2026-06-05T12:09:50.632Z
Link: CVE-2026-11372
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T17:45:05Z