CVE-2019-11292: Pivotal Software Operations Manager
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
Affected products
- Pivotal Software Operations Manager: from 2.4.0, before 2.4.27 (fixed in 2.4.27); from 2.5.0, before 2.5.24 (fixed in 2.5.24); from 2.6.0, before 2.6.16 (fixed in 2.6.16); from 2.7.0, before 2.7.5 (fixed in 2.7.5)
Published 2020-01-09. Last modified 2026-06-17.