Linuxfoundation
Linuxfoundation Zowe API Mediation Layer: vulnerabilidades y CVE
Linuxfoundation Zowe API Mediation Layer tiene 3 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-9802 | Media (5.3) | 0.21% | — | 10 oct 2024 | The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger.… |
| CVE-2024-9798 | Media (5.3) | 0.23% | — | 10 oct 2024 | The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers. |
| CVE-2021-4314 | Media (5.3) | 0.44% | — | 18 ene 2023 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143… |