CVE-2024-9802

Published Oct 10, 2024

Last updated 2 months ago

Overview

Description
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.
Source
zowe-security@lists.openmainframeproject.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-312
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-312

Social media

Hype score
Not currently trending

Configurations