CVE Database
/

CVE-2019-11275

Back to search

CVE-2019-11275

Published: Oct 1, 2019

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

3.5

LOW

Description

Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.

VendorProductVersions

Pivotal

Apps Manager

affected
670 - < 670.0.7
affected
669 - < 669.0.13
affected
668 - < 668.0.21
affected
667 - < 667.0.22
affected
666 - < 666.0.36

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

None

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now