Generated remediation guidance and an executive summary. No account required.
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces that they should not have access to.
Use CWE-269, Pivotal Software vendor hub and Pivotal Application Service product page to widen CVE-2019-11280 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-11088, CVE-2018-11086 and CVE-2018-11044 for nearby disclosures in the same product family.