CVE-2019-11275
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.
Published:Oct 1, 2019
Last Modified:Nov 21, 2024
EPS:Oct 1, 2019
EPSS Score:0.00203
CVSS Score:4.3
Affected Products
Vendor
Product
Action
Vendor
Pivotal
Product
Apps Manager
Pivotal
Apps Manager
Vendor
Pivotal Software
Product
Pivotal Application Service
Pivotal Software
Pivotal Application Service
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
