CVE-2024-9802

MEDIUM

Linuxfoundation Zowe API Mediation Layer < 2.17.0 - Cleartext Storage

Title source: rule
STIX 2.1

Description

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.

Scores

CVSS v3 5.3
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
linuxfoundation/zowe_api_mediation_layer 2.11.0 - 2.17.0
Published Oct 10, 2024
Tracked Since Feb 18, 2026