« Volver al listado

CVE-2024-9798

Estado: AnalizadaMedia (5.3)—

The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-9798",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-9798",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-10T14:16:37.423471Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "zowe-security@lists.openmainframeproject.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "zowe-security@lists.openmainframeproject.org",
      "affectedData": [
        {
          "vendor": "Open Mainframe Project",
          "product": "Zowe",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.18.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "1.28.8",
              "versionType": "semver"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*"
          ],
          "vendor": "linuxfoundation",
          "product": "zowe_api_mediation_layer",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.18.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "1.28.8",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-10T08:15:04.207",
  "references": [
    {
      "url": "https://github.com/zowe/api-layer",
      "tags": [
        "Product"
      ],
      "source": "zowe-security@lists.openmainframeproject.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-312"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-312"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers."
    },
    {
      "lang": "es",
      "value": "El endpoint de salud es público, por lo que todos pueden ver una lista de todos los servicios. Es información potencialmente valiosa para los atacantes."
    }
  ],
  "lastModified": "2026-06-17T08:25:16.890",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "412BFD66-17AB-406D-8C88-F76896DCD663",
              "versionEndExcluding": "1.28.8",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80068574-74E5-4A47-B442-7457F42AA879",
              "versionEndExcluding": "2.18.0",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "zowe-security@lists.openmainframeproject.org"
}