Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.21% | — | Linuxfoundation Zowe API Mediation Layer | 10/10/2024 | 17/6/2026 | The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also… | |
| Analizada | Media (5.3) | 0.23% | — | Linuxfoundation Zowe API Mediation Layer | 10/10/2024 | 17/6/2026 | The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers. | |
| Modificada | Media (5.3) | 0.44% | — | Linuxfoundation Zowe API Mediation Layer | 18/1/2023 | 17/6/2026 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What happens is that the services using the ZAAS… |