Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2019-11275 Details

Description

Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-1236Improper Neutralization of Formula Elements in a CSV File[email protected]
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')[email protected]

Affected Products

ProductVersions
pivotal apps manager
>= 666.0.0, < 666.0.36
>= 667.0.0, < 667.0.22
>= 668.0.0, < 668.0.21
>= 669.0.0, < 669.0.13
>= 670.0.0, < 670.0.7

CPE

  • cpe:2.3:a:pivotal:apps_manager:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
pivotal software pivotal application service
>= 2.3.0, <= 2.3.18
>= 2.4.0, <= 2.4.14
>= 2.5.0, <= 2.5.1
>= 2.6.0, <= 2.6.5

CPE

  • cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2019-11275
NVD Published Date:
Oct 1, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2019-11275 Details - Not Deferred