PT-2024-39845 · Zowe · Zowe

Pavel Jareš

·

Published

2024-10-10

·

Updated

2024-12-19

·

CVE-2024-9798

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zowe versions 1.0.0 through 1.28.8 Zowe versions 2.0.0 through 2.18.0
Description The health endpoint is public, allowing everybody to see a list of all services, which is potentially valuable information for attackers.
Recommendations For Zowe versions 1.0.0 through 1.28.8, upgrade to version 2.18.0 or later to safeguard services. For Zowe versions 2.0.0 through 2.18.0, upgrade to version 2.18.0 or later to safeguard services.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-9798

Affected Products

Zowe