CVE-2024-9802

Source
https://cve.org/CVERecord?id=CVE-2024-9802
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9802.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9802
Published
2024-10-10T07:41:03.374Z
Modified
2026-07-15T01:49:00.691613664Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C CVSS Calculator
Summary
Conformance validation endpoint discloses detail about service to unauthenticated users
Details

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9802.json",
    "cna_assigner": "Zowe"
}
References

Affected packages

Git / github.com/zowe/api-layer

Affected ranges

Type
GIT
Repo
https://github.com/zowe/api-layer
Events
Database specific
{
    "cpe": "cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "2.11.0"
        },
        {
            "fixed": "2.17.0"
        }
    ]
}

Affected versions

Zowe_2.*
Zowe_2.12.0
Zowe_2.13.0
Zowe_2.14.0
Zowe_2.15.0
Zowe_2.16.0
v2.*
v2.11.0
v2.11.1
v2.11.2
v2.11.3
v2.11.4
v2.11.5
v2.12.0
v2.12.1
v2.12.2
v2.12.3
v2.12.4
v2.12.5
v2.12.6
v2.12.7
v2.12.8
v2.12.9
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.13.4
v2.13.5
v2.13.6
v2.13.7
v2.14.0
v2.14.1
v2.14.2
v2.14.3
v2.14.4
v2.14.5
v2.14.6
v2.14.7
v2.14.8
v2.15.0
v2.15.1
v2.16.0
v2.16.1
v2.16.2
v2.16.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9802.json"