IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Project Subscriptions

Vendors Products
Tririga Application Platform Subscribe
Advisories

No advisories yet.

Fixes

Solution

An holistic approach has been implemented to address XSS vulnerabilities across the application as part of IBM TRIRIGA Application Platform 5.0.4 GA. This vulnerability is also part of it. Customers using affected versions of IBM TRIRIGA should upgrade to IBM TRIRIGA Application Platform 5.0.4 GA or a later supported release containing the fix. IBM recommends applying the latest available maintenance to ensure protection against this vulnerability. Reference : https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ETivoli&product[…]GA+Application+Platform&release=5.0.4&platform=All&function=all https://www.ibm.com/support/fixcentral/swg/selectFixes


Workaround

No workaround given by the vendor.

History

Mon, 22 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM TRIRIGA Cross-Site Scripting Vulnerability
First Time appeared Ibm
Ibm tririga Application Platform
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:tririga_application_platform:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tririga_application_platform:5.0.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm tririga Application Platform
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-06-22T15:57:43.139Z

Reserved: 2026-06-05T12:09:50.632Z

Link: CVE-2026-11372

cve-icon Vulnrichment

Updated: 2026-06-22T15:57:38.741Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-22T17:45:05Z

Weaknesses