Tririga Application Platform IBM Tririga Application Platform

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Tririga Application Platform.

By the Year

In 2026 there have been 1 vulnerability in IBM Tririga Application Platform with an average score of 5.4 out of ten. Tririga Application Platform did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 1 5.40
2025 0 0.00
2024 0 0.00
2023 3 5.93
2022 0 0.00
2021 0 0.00
2020 1 7.50
2019 3 5.20

It may take a day or so for new Tririga Application Platform vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Tririga Application Platform Security Vulnerabilities

IBM TRIRIGA App Platform 5.0.2-5.0.3 XSS via Authenticated Web UI
CVE-2026-11372 5.4 - Medium - June 22, 2026

IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

XSS

IBM TRIRIGA Remote Info Disclosure via detailed error 3.0-4.4
CVE-2020-4868 5.3 - Medium - July 31, 2023

IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190744.

Generation of Error Message Containing Sensitive Information

IBM TRIRIGA 4.0 XXE Vulnerability in XML Data Processing
CVE-2023-27876 7.1 - High - April 07, 2023

IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249975.

XXE

IBM TRIRIGA XSS via UI 4.0
CVE-2022-43914 5.4 - Medium - April 07, 2023

IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 241036.

XSS

IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages
CVE-2020-4277 7.5 - High - April 17, 2020

IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an attacker formulate future attacks. IBM X-Force ID: 175993.

Information Disclosure

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user
CVE-2018-2008 - May 07, 2019

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that could aid in further attacks against the system. IBM X-Force ID: 155146.

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user
CVE-2019-4207 3.3 - Low - May 07, 2019

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that could be used in further attacks against the system. IBM X-Force ID: 159148.

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data
CVE-2019-4208 7.1 - High - May 07, 2019

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 159129.

XXE

IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim
CVE-2017-1465 - December 07, 2017

IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 128464.

Builder tools running in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability
CVE-2017-1371 - July 21, 2017

Builder tools running in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute Builder tool actions they do not have access to. IBM X-Force ID: 126864.

IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting
CVE-2017-1372 - July 21, 2017

IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126865.

Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability
CVE-2017-1373 - July 21, 2017

Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.

Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5
CVE-2017-1374 - July 21, 2017

Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to the system. IBM X-Force ID: 126867.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Tririga Application Platform or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe