CVE-2024-9802

MEDIUM

Zowe API Mediation Layer 2.11.0-2.16.9 - Information Exposure via Conformance Validation Endpoint

Title source: llm
STIX 2.1

Description

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0020
EPSS Percentile 9.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
linuxfoundation/zowe_api_mediation_layer 2.11.0 - 2.17.0
Published Oct 10, 2024
Tracked Since Feb 18, 2026