PT-2024-39845 · Zowe · Zowe

·

CVE-2024-9798

·

Published

2024-10-10

·

Updated

2024-12-19

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zowe versions 1.0.0 through 1.28.8 Zowe versions 2.0.0 through 2.18.0
Description The health endpoint is public, allowing everybody to see a list of all services, which is potentially valuable information for attackers.
Recommendations For Zowe versions 1.0.0 through 1.28.8, upgrade to version 2.18.0 or later to safeguard services. For Zowe versions 2.0.0 through 2.18.0, upgrade to version 2.18.0 or later to safeguard services.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9798

Affected Products

Zowe