Zowe API Mediation Layer
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-9798 | Cri | 0.59 | 9.0 | 0.00 | Oct 10, 2024 | The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers. | ||
| CVE-2024-9802 | Med | 0.34 | 5.3 | 0.00 | Oct 10, 2024 | The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to… | ||
| CVE-2021-4314 | Med | 0.34 | 5.3 | 0.00 | Jan 18, 2023 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What… |
- risk 0.59cvss 9.0epss 0.00
The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
- risk 0.34cvss 5.3epss 0.00
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to…
- risk 0.34cvss 5.3epss 0.00
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What…